|
246231
|
9.8 |
CRITICAL
Network
|
fasterxml debian oracle netapp redhat
|
jackson-databind debian_linux primavera_unifier jd_edwards_enterpriseone_tools primavera_p6_enterprise_project_portfolio_management banking_platform jdeveloper retail_merchandisi…
|
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-14718
|
2024-11-21 12:49 |
2019-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246232
|
5.4 |
MEDIUM
Network
|
mondula
|
multi_step_form
|
The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14846
|
2024-11-21 12:49 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246233
|
6.3 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s6_firmware
|
Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (wh…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14856
|
2024-11-21 12:49 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246234
|
6.3 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s6_firmware
|
Buffer overflow in dhd_bus_flow_ring_flush_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 allow an attacker (who has obtained code exec…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14855
|
2024-11-21 12:49 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246235
|
6.3 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s6_firmware
|
Buffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (wh…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14854
|
2024-11-21 12:49 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246236
|
4.3 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s6_firmware
|
A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an atta…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-14853
|
2024-11-21 12:49 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246237
|
6.3 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s6_firmware
|
Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has ob…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14852
|
2024-11-21 12:49 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246238
|
4.3 |
MEDIUM
Network
|
theforeman
|
katello
|
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal …
|
-
|
CVE-2018-14623
|
2024-11-21 12:49 |
2018-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246239
|
9.8 |
CRITICAL
Network
|
drobo
|
5n2_firmware
|
Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure token generation.
|
CWE-287
Improper Authentication
|
CVE-2018-14709
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246240
|
9.8 |
CRITICAL
Network
|
drobo
|
5n2_firmware
|
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.
|
CWE-287
Improper Authentication
|
CVE-2018-14708
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|