|
248101
|
5.5 |
MEDIUM
Local
|
intel
|
extreme_tuning_utility
|
Buffer overflow in installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially cause a buffer overflow potentially leading to a denial of service via loc…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12151
|
2024-11-21 12:44 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248102
|
6.7 |
MEDIUM
Local
|
intel
|
extreme_tuning_utility
|
Escalation of privilege in Installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially execute code or disclose information as administrator via local ac…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12150
|
2024-11-21 12:44 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248103
|
5.5 |
MEDIUM
Local
|
intel
|
extreme_tuning_utility
|
Buffer overflow in input handling in Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially deny service to the application via local access.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12149
|
2024-11-21 12:44 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248104
|
7.8 |
HIGH
Local
|
intel
|
driver_\&_support_assistant
|
Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via local access.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-12148
|
2024-11-21 12:44 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248105
|
7.4 |
HIGH
Network
|
apache oracle
|
activemq flexcube_private_banking enterprise_repository
|
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client …
|
CWE-295
Improper Certificate Validation
|
CVE-2018-11775
|
2024-11-21 12:44 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248106
|
6.1 |
MEDIUM
Network
|
myadrenalin
|
adrenalin
|
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML respon…
|
CWE-79
Cross-site Scripting
|
CVE-2018-12234
|
2024-11-21 12:44 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248107
|
5.9 |
MEDIUM
Network
|
symantec
|
norton_password_manager
|
The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likeliho…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-12240
|
2024-11-21 12:44 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248108
|
8.1 |
HIGH
Network
|
apache netapp oracle
|
struts snapcenter oncommand_workflow_automation oncommand_insight active_iq_unified_manager mysql_enterprise_monitor enterprise_manager_base_platform communications_policy_manage…
|
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: …
|
NVD-CWE-noinfo
|
CVE-2018-11776
|
2024-11-21 12:44 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248109
|
7.5 |
HIGH
Network
|
nodejs redhat
|
node.js openshift_container_platform
|
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()`…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12115
|
2024-11-21 12:44 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248110
|
8.8 |
HIGH
Network
|
litecart
|
litecart
|
admin/vqmods.app/vqmods.inc.php in LiteCart before 2.1.3 allows remote authenticated attackers to upload a malicious file (resulting in remote code execution) by using the text/xml or application/xml…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-12256
|
2024-11-21 12:44 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|