|
247871
|
6.8 |
MEDIUM
Physics
|
tianocore
|
edk_ii
|
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12183
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247872
|
6.7 |
MEDIUM
Local
|
tianocore
|
edk_ii
|
Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local acce…
|
CWE-441
Confused Deputy
|
CVE-2018-12182
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247873
|
6.0 |
MEDIUM
Local
|
tianocore
|
edk_ii
|
Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12181
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247874
|
8.8 |
HIGH
Network
|
tianocore opensuse
|
edk_ii leap
|
Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12180
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247875
|
7.8 |
HIGH
Local
|
tianocore
|
edk_ii
|
Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
|
NVD-CWE-noinfo
|
CVE-2018-12179
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247876
|
9.1 |
CRITICAL
Network
|
tianocore
|
edk_ii
|
Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12178
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247877
|
7.5 |
HIGH
Network
|
fasterxml debian fedoraproject oracle redhat
|
jackson-databind debian_linux fedora jd_edwards_enterpriseone_tools retail_merchandising_system openshift_container_platform jboss_enterprise_application_platform single_sign-on<…
|
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JD…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-12023
|
2024-11-21 12:44 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247878
|
7.5 |
HIGH
Network
|
fasterxml debian fedoraproject oracle redhat
|
jackson-databind debian_linux fedora jd_edwards_enterpriseone_tools retail_merchandising_system openshift_container_platform jboss_enterprise_application_platform single_sign-on<…
|
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db j…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-12022
|
2024-11-21 12:44 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247879
|
7.5 |
HIGH
Network
|
apache
|
heron
|
When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the dire…
|
CWE-22
Path Traversal
|
CVE-2018-11789
|
2024-11-21 12:44 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247880
|
3.3 |
LOW
Local
|
intel
|
graphics_driver
|
Buffer leakage in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (…
|
CWE-200
Information Exposure
|
CVE-2018-12224
|
2024-11-21 12:44 |
2019-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|