|
247921
|
8.8 |
HIGH
Network
|
cisco
|
unified_communications_domain_manager
|
A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) att…
|
CWE-352
Origin Validation Error
|
CVE-2018-0364
|
2024-11-21 12:38 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247922
|
8.8 |
HIGH
Network
|
cisco
|
unified_communications_manager_im_and_presence_service
|
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could allow an unauthenticated, remote attacker to conduct a cross-…
|
CWE-352
Origin Validation Error
|
CVE-2018-0363
|
2024-11-21 12:38 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247923
|
4.3 |
MEDIUM
Physics
|
cisco
|
5400_enterprise_network_compute_system_firmware 5100_enterprise_network_compute_system_firmware ucs-e160s-m3_firmware ucs-e160s-k9_firmware ucs-e180d-m3_firmware ucs-e180d-k9_firmware<…
|
A vulnerability in BIOS authentication management of Cisco 5000 Series Enterprise Network Compute System and Cisco Unified Computing (UCS) E-Series Servers could allow an unauthenticated, local attac…
|
CWE-287
Improper Authentication
|
CVE-2018-0362
|
2024-11-21 12:38 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247924
|
5.5 |
MEDIUM
Local
|
cisco
|
meeting_server
|
A vulnerability in the session identification management functionality of the web-based management interface for Cisco Meeting Server could allow an unauthenticated, local attacker to hijack a valid …
|
CWE-384
Session Fixation
|
CVE-2018-0359
|
2024-11-21 12:38 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247925
|
7.5 |
HIGH
Network
|
cisco
|
telepresence_video_communication_server
|
A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) co…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-0358
|
2024-11-21 12:38 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247926
|
7.8 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device. The vulnerabilit…
|
CWE-863
Incorrect Authorization
|
CVE-2018-0337
|
2024-11-21 12:38 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247927
|
4.7 |
MEDIUM
Local
|
gnupg canonical debian redhat oracle
|
libgcrypt ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ansible_tower traffic_director
|
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2018-0495
|
2024-11-21 12:38 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247928
|
7.5 |
HIGH
Network
|
dinknetwork debian
|
dfarc2 dfarc debian_linux
|
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the …
|
CWE-22
Path Traversal
|
CVE-2018-0496
|
2024-11-21 12:38 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247929
|
7.5 |
HIGH
Network
|
openssl debian canonical nodejs
|
openssl debian_linux ubuntu_linux node.js
|
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long pe…
|
CWE-320
Key Management Errors
|
CVE-2018-0732
|
2024-11-21 12:38 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247930
|
6.1 |
MEDIUM
Network
|
cisco
|
webex_meetings
|
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0357
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|