|
246961
|
7.8 |
HIGH
Local
|
debian canonical linux redhat
|
debian_linux ubuntu_linux linux_kernel enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in snd_rawmidi_input_params() and snd_rawmidi_output_status() whi…
|
-
|
CVE-2018-10902
|
2024-11-21 12:42 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246962
|
4.3 |
MEDIUM
Adjacent
|
intel
|
lldptool
|
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the …
|
-
|
CVE-2018-10932
|
2024-11-21 12:42 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246963
|
8.8 |
HIGH
Network
|
spice_project debian canonical redhat
|
spice debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization_host virtualization enterprise_linux_server_eus
|
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authenticat…
|
CWE-20
Improper Input Validation
|
CVE-2018-10873
|
2024-11-21 12:42 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246964
|
9.8 |
CRITICAL
Network
|
nasdaq
|
bwise
|
The JMX/RMI interface in Nasdaq BWise 5.0 does not require authentication for an SAP BO Component, which allows remote attackers to execute arbitrary code via a session on port 81.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-11247
|
2024-11-21 12:42 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246965
|
6.5 |
MEDIUM
Network
|
pulpproject
|
pulp
|
pulp 2.16.x and possibly older is vulnerable to an improper path parsing. A malicious user or a malicious iso feed repository can write to locations accessible to the 'apache' user. This may lead to …
|
-
|
CVE-2018-10917
|
2024-11-21 12:42 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246966
|
6.2 |
MEDIUM
Local
|
redhat
|
certification
|
An uncontrolled resource consumption flaw has been discovered in redhat-certification in the way documents are loaded. A remote attacker may provide an existing but invalid XML file which would be op…
|
-
|
CVE-2018-10864
|
2024-11-21 12:42 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246967
|
8.1 |
HIGH
Network
|
dell
|
emc_integrated_data_protection_appliance emc_data_protection_advisor
|
Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in…
|
CWE-611
XXE
|
CVE-2018-11048
|
2024-11-21 12:42 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246968
|
7.8 |
HIGH
Local
|
dell
|
wyse_management_suite
|
Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executa…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2018-11063
|
2024-11-21 12:42 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246969
|
7.5 |
HIGH
Network
|
smartmesh_project ugtoken_project gg_token_project first_project mtc_project mesh_project
|
smartmesh ugtoken gg_token first mtc mesh
|
The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 token, allow attackers to accomplish an unauthorized transfer of digital assets …
|
NVD-CWE-noinfo
|
CVE-2018-10769
|
2024-11-21 12:42 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246970
|
8.1 |
HIGH
Network
|
canonical debian postgresql
|
ubuntu_linux debian_linux postgresql
|
It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE…
|
CWE-863
Incorrect Authorization
|
CVE-2018-10925
|
2024-11-21 12:42 |
2018-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|