|
246311
|
7.5 |
HIGH
Network
|
python canonical debian fedoraproject opensuse redhat
|
python ubuntu_linux debian_linux fedora leap enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML docu…
|
CWE-909
Missing Initialization of Resource
|
CVE-2018-14647
|
2024-11-21 12:49 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246312
|
7.0 |
HIGH
Network
|
linux debian canonical redhat
|
linux_kernel debian_linux ubuntu_linux enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_eus
|
A security flaw was found in the chap_server_compute_md5() function in the ISCSI target code in the Linux kernel in a way an authentication request from an ISCSI initiator is processed. An unauthenti…
|
-
|
CVE-2018-14633
|
2024-11-21 12:49 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246313
|
5.8 |
MEDIUM
Local
|
honeywell
|
cn80 ct40 ct60 eda50 eda50k eda60k eda70 ck75 cn51 cn75 cn75e d75e ct50 eda51
|
On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN75 running Android OS 6.0, CN75e running Android O…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14825
|
2024-11-21 12:49 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246314
|
7.5 |
HIGH
Network
|
webpack.js
|
webpack-dev-server
|
An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which …
|
CWE-20
Improper Input Validation
|
CVE-2018-14732
|
2024-11-21 12:49 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246315
|
7.5 |
HIGH
Network
|
parceljs
|
parcel
|
An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for…
|
CWE-200
Information Exposure
|
CVE-2018-14731
|
2024-11-21 12:49 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246316
|
7.5 |
HIGH
Network
|
browserify-hot_module_replacement_project
|
browserify-hot_module_replacement
|
An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replac…
|
CWE-200
Information Exposure
|
CVE-2018-14730
|
2024-11-21 12:49 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246317
|
6.1 |
MEDIUM
Network
|
subsonic
|
subsonic
|
An issue was discovered in Subsonic 6.1.1. The music tags feature is affected by three stored cross-site scripting vulnerabilities in the c0-param2, c0-param3, and c0-param4 parameters to dwr/call/pl…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14691
|
2024-11-21 12:49 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246318
|
6.1 |
MEDIUM
Network
|
subsonic
|
subsonic
|
An issue was discovered in Subsonic 6.1.1. The general settings are affected by two stored cross-site scripting vulnerabilities in the title and subtitle parameters to generalSettings.view that could…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14690
|
2024-11-21 12:49 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246319
|
6.1 |
MEDIUM
Network
|
subsonic
|
subsonic
|
An issue was discovered in Subsonic 6.1.1. The transcoding settings are affected by five stored cross-site scripting vulnerabilities in the name[x], sourceformats[x], targetFormat[x], step1[x], and s…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14689
|
2024-11-21 12:49 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246320
|
6.1 |
MEDIUM
Network
|
subsonic
|
subsonic
|
An issue was discovered in Subsonic 6.1.1. The radio settings are affected by three stored cross-site scripting vulnerabilities in the name[x], streamUrl[x], homepageUrl[x] parameters (where x is an …
|
CWE-79
Cross-site Scripting
|
CVE-2018-14688
|
2024-11-21 12:49 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|