|
248911
|
8.8 |
HIGH
Adjacent
|
buffalo
|
wxr-1900dhp2_firmware
|
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-0521
|
2024-11-21 12:38 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248912
|
7.5 |
HIGH
Network
|
torproject
|
tor
|
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be adde…
|
CWE-416
Use After Free
|
CVE-2018-0491
|
2024-11-21 12:38 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248913
|
7.5 |
HIGH
Network
|
torproject debian
|
tor debian_linux
|
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-0490
|
2024-11-21 12:38 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248914
|
6.5 |
MEDIUM
Network
|
shibboleth debian arubanetworks
|
xmltooling-c debian_linux clearpass
|
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-0489
|
2024-11-21 12:38 |
2018-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248915
|
8.8 |
HIGH
Network
|
fsi
|
fs010w_firmware
|
Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2018-0520
|
2024-11-21 12:38 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248916
|
4.8 |
MEDIUM
Network
|
fsi
|
fs010w_firmware
|
Cross-site scripting vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0519
|
2024-11-21 12:38 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248917
|
5.9 |
MEDIUM
Network
|
linecorp
|
line
|
LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certi…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-0518
|
2024-11-21 12:38 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248918
|
7.8 |
HIGH
Local
|
flets
|
address_selection_tool
|
Untrusted search path vulnerability in FLET'S v4 / v6 address selection tool allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-0516
|
2024-11-21 12:38 |
2018-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248919
|
7.8 |
HIGH
Local
|
flets
|
azukeru_backup_tool
|
Untrusted search path vulnerability in "FLET'S Azukeru Backup Tool" version 1.5.2.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-0515
|
2024-11-21 12:38 |
2018-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248920
|
4.7 |
MEDIUM
Local
|
microsoft
|
windows_7 windows_server_2008 windows_server_2012
|
The Windows kernel in Windows 7 SP1, Windows Server 2008 SP2 and R2, and Windows Server 2012 allows an information disclosure vulnerability due to the way memory is initialized, aka "Windows Kernel I…
|
CWE-665
Improper Initialization
|
CVE-2018-0810
|
2024-11-21 12:38 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|