|
249611
|
7.8 |
HIGH
Local
|
cisco
|
nx-os
|
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device. The vulnerabilit…
|
CWE-863
Incorrect Authorization
|
CVE-2018-0337
|
2024-11-21 12:38 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249612
|
4.7 |
MEDIUM
Local
|
gnupg canonical debian redhat oracle
|
libgcrypt ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ansible_tower traffic_director
|
Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2018-0495
|
2024-11-21 12:38 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249613
|
7.5 |
HIGH
Network
|
dinknetwork debian
|
dfarc2 dfarc debian_linux
|
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the …
|
CWE-22
Path Traversal
|
CVE-2018-0496
|
2024-11-21 12:38 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249614
|
7.5 |
HIGH
Network
|
openssl debian canonical nodejs
|
openssl debian_linux ubuntu_linux node.js
|
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long pe…
|
CWE-320
Key Management Errors
|
CVE-2018-0732
|
2024-11-21 12:38 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249615
|
6.1 |
MEDIUM
Network
|
cisco
|
webex_meetings
|
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0357
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249616
|
6.1 |
MEDIUM
Network
|
cisco
|
webex_meetings
|
A vulnerability in the web framework of Cisco WebEx could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0356
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249617
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross-frame scripting (XFS) attack against the user of …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2018-0355
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249618
|
6.1 |
MEDIUM
Network
|
cisco
|
unity_connection
|
A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of …
|
CWE-79
Cross-site Scripting
|
CVE-2018-0354
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249619
|
6.7 |
MEDIUM
Local
|
cisco
|
wide_area_application_services
|
A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to elevate their privilege level to root. …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-0352
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249620
|
5.4 |
MEDIUM
Network
|
cisco
|
unified_communications_manager
|
A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack aga…
|
CWE-79
Cross-site Scripting
|
CVE-2018-0340
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|