|
246961
|
7.8 |
HIGH
Local
|
intel
|
graphics_driver
|
Pointer corruption in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5057 (aka 15.36.x.5057) and 20.19.x.5058 (aka 15.40.x.5058) may allow an unauth…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12152
|
2024-11-21 12:44 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246962
|
7.8 |
HIGH
Local
|
intel
|
datacenter_nvme rapid_storage_technology client_nvme
|
Permissions in the driver pack installers for Intel NVMe before version 4.0.0.1007 and Intel RSTe before version 4.7.0.2083 may allow an authenticated user to potentially escalate privilege via local…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-12131
|
2024-11-21 12:44 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246963
|
7.5 |
HIGH
Network
|
apache
|
tika
|
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the do…
|
CWE-611
XXE
|
CVE-2018-11796
|
2024-11-21 12:44 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246964
|
5.5 |
MEDIUM
Local
|
apache fedoraproject oracle
|
pdfbox fedora retail_xstore_point_of_service
|
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
|
NVD-CWE-noinfo
|
CVE-2018-11797
|
2024-11-21 12:44 |
2018-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246965
|
8.8 |
HIGH
Network
|
apache
|
ranger
|
UnixAuthenticationService in Apache Ranger 1.2.0 was updated to correctly handle user input to avoid Stack-based buffer overflow. Versions prior to 1.2.0 should be upgraded to 1.2.0
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11778
|
2024-11-21 12:44 |
2018-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246966
|
5.3 |
MEDIUM
Physics
|
opcfoundation
|
ua-.netstandard ua-.net-legacy
|
Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords.
|
CWE-295
Improper Certificate Validation
|
CVE-2018-12087
|
2024-11-21 12:44 |
2018-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246967
|
4.3 |
MEDIUM
Network
|
apache debian canonical netapp redhat oracle
|
tomcat debian_linux ubuntu_linux snap_creator_framework enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_li…
|
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/f…
|
CWE-601
Open Redirect
|
CVE-2018-11784
|
2024-11-21 12:44 |
2018-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246968
|
7.6 |
HIGH
Physics
|
intel lenovo
|
core_i3 core_i5 core_i7 core_i9 thinkpad_x1_yoga thinkpad_x1_tablet thinkpad_x1_carbon thinkpad_11e thinkpad_p51s thinkpad_p71 thinkpad_t470 thinkpad_t470p thinkpa…
|
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation …
|
CWE-287
Improper Authentication
|
CVE-2018-12169
|
2024-11-21 12:44 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246969
|
8.8 |
HIGH
Adjacent
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9635m_firmware mdm9640_firmware mdm9645_firmware mdm9655_firmware msm8909w_firmware msm8996au_firmware sd210_firmware sd212_firmware
|
In Snapdragon (Mobile, Wear) in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/…
|
CWE-415
Double Free
|
CVE-2018-11982
|
2024-11-21 12:44 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246970
|
8.8 |
HIGH
Adjacent
|
symantec
|
messaging_gateway
|
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity…
|
CWE-611
XXE
|
CVE-2018-12243
|
2024-11-21 12:44 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|