|
247451
|
8.8 |
HIGH
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the ta…
|
CWE-416
Use After Free
|
CVE-2018-11617
|
2024-11-21 12:43 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247452
|
7.5 |
HIGH
Network
|
intuit
|
lacerte
|
Intuit Lacerte 2017 for Windows in a client/server environment transfers the entire customer list in cleartext over SMB, which allows attackers to (1) obtain sensitive information by sniffing the net…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2018-11338
|
2024-11-21 12:43 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247453
|
9.8 |
CRITICAL
Network
|
asus
|
hg100_firmware
|
ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution.
|
CWE-287
Improper Authentication
|
CVE-2018-11491
|
2024-11-21 12:43 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247454
|
7.5 |
HIGH
Network
|
siemens
|
dnp3_tcp_firmware iec_61850_firmware iec104_firmware modbus_tcp_firmware profinet_io_firmware cp100_firmware cp200_firmware cp300_firmware
|
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware var…
|
CWE-20
Improper Input Validation
|
CVE-2018-11452
|
2024-11-21 12:43 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247455
|
7.5 |
HIGH
Network
|
siemens
|
dnp3_tcp_firmware iec_61850_firmware iec104_firmware modbus_tcp_firmware profinet_io_firmware cp100_firmware cp200_firmware cp300_firmware
|
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware var…
|
CWE-20
Improper Input Validation
|
CVE-2018-11451
|
2024-11-21 12:43 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247456
|
9.8 |
CRITICAL
Network
|
apache
|
openwhisk
|
In Docker Skeleton Runtime for Apache OpenWhisk, a Docker action inheriting the Docker tag openwhisk/dockerskeleton:1.3.0 (or earlier) may allow an attacker to replace the user function inside the co…
|
NVD-CWE-noinfo
|
CVE-2018-11757
|
2024-11-21 12:43 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247457
|
9.8 |
CRITICAL
Network
|
apache
|
openwhisk
|
In PHP Runtime for Apache OpenWhisk, a Docker action inheriting one of the Docker tags openwhisk/action-php-v7.2:1.0.0 or openwhisk/action-php-v7.1:1.0.1 (or earlier) may allow an attacker to replace…
|
NVD-CWE-noinfo
|
CVE-2018-11756
|
2024-11-21 12:43 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247458
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central
|
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (priv…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-11716
|
2024-11-21 12:43 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247459
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central
|
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base6…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-11717
|
2024-11-21 12:43 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247460
|
8.0 |
HIGH
Adjacent
|
debian videolan
|
debian_linux vlc_media_player
|
VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result i…
|
CWE-416
Use After Free
|
CVE-2018-11529
|
2024-11-21 12:43 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|