|
246851
|
7.5 |
HIGH
Network
|
ethercartel
|
ether_cartel
|
The DrugDealer function of a smart contract implementation for Ether Cartel, an Ethereum game, allows attackers to take over the contract's ownership, aka ceoAnyone. After that, all the digital asset…
|
NVD-CWE-noinfo
|
CVE-2018-11329
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246852
|
7.5 |
HIGH
Network
|
wizardmac
|
readstat
|
sas/readstat_sas7bcat_read.c in libreadstat.a in ReadStat 0.1.1 has an infinite loop.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-11365
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246853
|
7.5 |
HIGH
Network
|
wizardmac
|
readstat
|
sav_parse_machine_integer_info_record in spss/readstat_sav_read.c in libreadstat.a in ReadStat 0.1.1 has a memory leak related to an iconv_open call.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-11364
|
2024-11-21 12:43 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246854
|
9.8 |
CRITICAL
Network
|
octopus
|
octopus_server
|
In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-11320
|
2024-11-21 12:43 |
2018-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246855
|
9.1 |
CRITICAL
Network
|
myscada
|
mypro
|
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-11311
|
2024-11-21 12:43 |
2018-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246856
|
7.5 |
HIGH
Network
|
syntastic_project debian
|
syntastic debian_linux
|
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be e…
|
CWE-22
Path Traversal
|
CVE-2018-11319
|
2024-11-21 12:43 |
2018-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246857
|
6.5 |
MEDIUM
Adjacent
|
radiothermostat
|
ct50_firmware ct80_firmware
|
The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can result in remote device temperature control, as demonst…
|
CWE-20
Improper Input Validation
|
CVE-2018-11315
|
2024-11-21 12:43 |
2018-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246858
|
6.5 |
MEDIUM
Network
|
podofo_project
|
podofo
|
An issue was discovered in PoDoFo 0.9.5. The function PdfDocument::Append() in PdfDocument.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and appli…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-11256
|
2024-11-21 12:43 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246859
|
7.5 |
HIGH
Network
|
axiosys
|
bento4
|
The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allows remote attackers to cause a denial of service (application crash), related to a memory allocation failure, as demonstrated by m…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-10790
|
2024-11-21 12:42 |
2021-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246860
|
7.5 |
HIGH
Network
|
redhat
|
certification
|
redhat-certification 7 does not properly restrict the number of recursive definitions of entities in XML documents, allowing an unauthenticated user to run a "Billion Laugh Attack" by replying to XML…
|
CWE-400 CWE-776
Uncontrolled Resource Consumption XML Entity Expansion
|
CVE-2018-10868
|
2024-11-21 12:42 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|