|
246891
|
7.5 |
HIGH
Network
|
nodejs redhat
|
node.js enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux
|
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-12121
|
2024-11-21 12:44 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246892
|
8.1 |
HIGH
Network
|
nodejs
|
node.js
|
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2018-12120
|
2024-11-21 12:44 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246893
|
7.5 |
HIGH
Network
|
nodejs suse
|
node.js suse_linux_enterprise_server suse_enterprise_storage suse_openstack_cloud
|
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, t…
|
NVD-CWE-Other
|
CVE-2018-12116
|
2024-11-21 12:44 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246894
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8909w_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_600_firmware …
|
When a malformed command is sent to the device programmer, an out-of-bounds access can occur in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MDM…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-11996
|
2024-11-21 12:44 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246895
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_430_firmware sd_450_firmware sd_…
|
SMMU secure camera logic allows secure camera controllers to access HLOS memory during session in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, M…
|
NVD-CWE-noinfo
|
CVE-2018-11994
|
2024-11-21 12:44 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246896
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd_425_firmware sd_…
|
Failure condition is not handled properly and the correct error code is not returned. It could cause unintended SUI behavior and create unintended SUI display in Snapdragon Automobile, Snapdragon Mob…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2018-11921
|
2024-11-21 12:44 |
2018-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246897
|
6.1 |
MEDIUM
Network
|
symantec
|
security_analytics
|
The Symantec Security Analytics (SA) 7.x prior to 7.3.4 Web UI is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker with knowledge of the SA web UI hostname or IP…
|
CWE-79
Cross-site Scripting
|
CVE-2018-12241
|
2024-11-21 12:44 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246898
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a partition name-check variable is not reset for every iteration which may cause improper te…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11995
|
2024-11-21 12:44 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246899
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper mounting lead to device node and executable to be run from /dsp/ which presents a p…
|
NVD-CWE-noinfo
|
CVE-2018-11956
|
2024-11-21 12:44 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246900
|
6.5 |
MEDIUM
Adjacent
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, the UPnP daemon should not be running out of box because it enables port forwarding without …
|
NVD-CWE-noinfo
|
CVE-2018-11946
|
2024-11-21 12:44 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|