|
247221
|
8.1 |
HIGH
Network
|
apache netapp oracle
|
struts snapcenter oncommand_workflow_automation oncommand_insight active_iq_unified_manager mysql_enterprise_monitor enterprise_manager_base_platform communications_policy_manage…
|
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: …
|
NVD-CWE-noinfo
|
CVE-2018-11776
|
2024-11-21 12:44 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247222
|
7.5 |
HIGH
Network
|
nodejs redhat
|
node.js openshift_container_platform
|
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()`…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12115
|
2024-11-21 12:44 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247223
|
8.8 |
HIGH
Network
|
litecart
|
litecart
|
admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code execution) by using the text/xml or application/xml…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-12256
|
2024-11-21 12:44 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247224
|
7.5 |
HIGH
Network
|
all-for-one
|
all_for_one
|
The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random value with publicly readable variables because the _seed value can be retrieve…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2018-12056
|
2024-11-21 12:44 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247225
|
7.5 |
HIGH
Network
|
remicoin_project
|
remicoin
|
An wrong logical check identified in the transferFrom function of a smart contract implementation for RemiCoin (RMC), an Ethereum ERC20 token, allows the attacker to steal tokens or conduct resultant…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2018-12230
|
2024-11-21 12:44 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247226
|
9.8 |
CRITICAL
Network
|
coreftp
|
core_ftp
|
Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12113
|
2024-11-21 12:44 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247227
|
6.5 |
MEDIUM
Adjacent
|
dlink d-link
|
dir-890l_firmware dir-885l\/r_firmware dir-895l\/r_firmware
|
An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/R with firmware 1.21B04beta04 and earlier devices …
|
CWE-863
Incorrect Authorization
|
CVE-2018-12103
|
2024-11-21 12:44 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247228
|
6.5 |
MEDIUM
Network
|
sylabs
|
singularity
|
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information …
|
CWE-200
Information Exposure
|
CVE-2018-12021
|
2024-11-21 12:44 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247229
|
7.5 |
HIGH
Network
|
ethereum
|
go_ethereum
|
The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access violation because of an integer signedness error for the array index, w…
|
CWE-129
Improper Validation of Array Index
|
CVE-2018-12018
|
2024-11-21 12:44 |
2018-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247230
|
6.1 |
MEDIUM
Network
|
invoiceplane
|
invoiceplane
|
An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12255
|
2024-11-21 12:44 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|