|
248371
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_7 windows_server_2008
|
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded …
|
CWE-200
Information Exposure
|
CVE-2018-0755
|
2024-11-21 12:38 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248372
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_10 windows_server_2016 windows_8.1 windows_server_2008 windows_7
|
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Window…
|
NVD-CWE-noinfo
|
CVE-2018-0742
|
2024-11-21 12:38 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248373
|
9.8 |
CRITICAL
Network
|
arm debian
|
mbed_tls debian_linux
|
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap c…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-0488
|
2024-11-21 12:38 |
2018-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248374
|
9.8 |
CRITICAL
Network
|
arm debian
|
mbed_tls debian_linux
|
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0487
|
2024-11-21 12:38 |
2018-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248375
|
7.8 |
HIGH
Local
|
kddi
|
anshin_net_security
|
Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-0517
|
2024-11-21 12:38 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248376
|
9.8 |
CRITICAL
Network
|
futomi
|
mp_form_mail_cgi
|
MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2018-0514
|
2024-11-21 12:38 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248377
|
6.1 |
MEDIUM
Network
|
mtssb.mt-systems
|
simple_booking
|
Cross-site scripting vulnerability in MTS Simple Booking C, MTS Simple Booking Business version 1.28.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vecto…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0513
|
2024-11-21 12:38 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248378
|
6.8 |
MEDIUM
Adjacent
|
iodata
|
hdl-xr_firmware hdl-xrw_firmware hdl-xr2u_firmware hdl-xr2uw_firmware hdl-xv_firmware hdl-xvw_firmware hdl-gt_firmware hdl-gtr_firmware hdl-a_firmware hdl-ah_firmware hd…
|
Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2018-0512
|
2024-11-21 12:38 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248379
|
6.1 |
MEDIUM
Network
|
meowapps
|
wp_retina_2x
|
Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0511
|
2024-11-21 12:38 |
2018-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248380
|
9.8 |
CRITICAL
Network
|
kkcald_project
|
kkcald
|
Buffer overflow in epg search result viewer (kkcald) 0.7.19 and earlier allows remote attackers to perform unintended operations or execute DoS (denial of service) attacks via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0510
|
2024-11-21 12:38 |
2018-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|