|
246571
|
9.8 |
CRITICAL
Network
|
ribboncommunications
|
sonus_sbc_1000_firmware sonus_sbc_2000_firmware sbc_swe_lite_web
|
A root privilege escalation vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows unauthorised access to privileged content via an unspecified vector. It affects the 1000…
|
CWE-862
Missing Authorization
|
CVE-2018-11541
|
2024-11-21 12:43 |
2018-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246572
|
6.1 |
MEDIUM
Network
|
jirafeau
|
jirafeau
|
script.php in Jirafeau before 3.4.1 is affected by two stored Cross-Site Scripting (XSS) vulnerabilities. These are stored within the shared files description file and allow the execution of a JavaSc…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11351
|
2024-11-21 12:43 |
2018-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246573
|
6.1 |
MEDIUM
Network
|
jirafeau
|
jirafeau
|
An issue was discovered in Jirafeau before 3.4.1. The file "search by name" form is affected by one Cross-Site Scripting vulnerability via the name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11350
|
2024-11-21 12:43 |
2018-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246574
|
8.8 |
HIGH
Network
|
jirafeau
|
jirafeau
|
The administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_by_name, search_by_hash, and search_link.
|
CWE-352
Origin Validation Error
|
CVE-2018-11349
|
2024-11-21 12:43 |
2018-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246575
|
7.8 |
HIGH
Local
|
google
|
android
|
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for M…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11304
|
2024-11-21 12:43 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246576
|
7.7 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9635m_firmware mdm9640_firmware mdm9650_firmware mdm9655_firmware msm8909w_firmware msm8996au_firmware sd_210_firmware sd_212_firmware<…
|
Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-11259
|
2024-11-21 12:43 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246577
|
7.8 |
HIGH
Local
|
qualcomm
|
sd_210_firmware sd_212_firmware sd_205_firmware sd_845_firmware sd_850_firmware
|
Permissions, Privileges, and Access Controls in TA in Snapdragon Mobile has an options that allows RPMB erase for secure devices in versions SD 210/SD 212/SD 205, SD 845, SD 850.
|
NVD-CWE-noinfo
|
CVE-2018-11257
|
2024-11-21 12:43 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246578
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_450_firmware s…
|
In ADSP RPC in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, a Use After Free condition can occur in versions MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD …
|
CWE-416
Use After Free
|
CVE-2018-11258
|
2024-11-21 12:43 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246579
|
7.5 |
HIGH
Network
|
atlant
|
atlant
|
ATLANT (ATL) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11429
|
2024-11-21 12:43 |
2018-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246580
|
7.5 |
HIGH
Network
|
genesis_vision
|
gvtoken
|
GVToken Genesis Vision (GVT) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11335
|
2024-11-21 12:43 |
2018-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|