|
246881
|
6.8 |
MEDIUM
Adjacent
|
polycom
|
realpresence_debut_firmware
|
An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the admin user's password via the admin web UI.
|
CWE-200
Information Exposure
|
CVE-2018-10946
|
2024-11-21 12:42 |
2019-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246882
|
4.8 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
Synacor Zimbra Admin UI in Zimbra Collaboration Suite before 8.8.0 beta 2 has Persistent XSS via mail addrs.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10948
|
2024-11-21 12:42 |
2019-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246883
|
6.5 |
MEDIUM
Network
|
cloudera
|
cloudera_manager
|
An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive cluster information.
|
CWE-200
Information Exposure
|
CVE-2018-10815
|
2024-11-21 12:42 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246884
|
7.5 |
HIGH
Network
|
beyondtrust
|
avecto_defendpoint
|
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's…
|
CWE-426
Untrusted Search Path
|
CVE-2018-10959
|
2024-11-21 12:42 |
2019-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246885
|
5.4 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform single_sign-on
|
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this …
|
CWE-79
Cross-site Scripting
|
CVE-2018-10934
|
2024-11-21 12:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246886
|
3.3 |
LOW
Local
|
bluez canonical
|
bluez ubuntu_linux
|
A bug in Bluez may allow for the Bluetooth Discoverable state being set to on when no Bluetooth agent is registered with the system. This situation could lead to the unauthorized pairing of certain B…
|
-
|
CVE-2018-10910
|
2024-11-21 12:42 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246887
|
7.5 |
HIGH
Network
|
powerdns
|
recursor authoritative
|
PowerDNS Authoritative Server 3.3.0 up to 4.1.4 excluding 4.1.5 and 4.0.6, and PowerDNS Recursor 3.2 up to 4.1.4 excluding 4.1.5 and 4.0.9, are vulnerable to a memory leak while parsing malformed rec…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-10851
|
2024-11-21 12:42 |
2018-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246888
|
5.5 |
MEDIUM
Local
|
pulsesecure
|
pulse_secure_desktop_client
|
Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-11002
|
2024-11-21 12:42 |
2018-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246889
|
6.7 |
MEDIUM
Local
|
dell vmware
|
emc_integrated_data_protection_appliance emc_avamar vsphere_data_protection
|
'getlogs' utility in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1 and 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2…
|
CWE-78
OS Command
|
CVE-2018-11077
|
2024-11-21 12:42 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246890
|
6.5 |
MEDIUM
Adjacent
|
dell vmware
|
emc_integrated_data_protection_appliance emc_avamar vsphere_data_protection
|
Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0 and 7.4.1 and Dell EMC Integrated Data Protection Appliance (IDPA) 2.0 are affected by an information exposure vulnerability. Avamar …
|
NVD-CWE-noinfo
|
CVE-2018-11076
|
2024-11-21 12:42 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|