|
247511
|
9.8 |
CRITICAL
Network
|
actiontec
|
web6000q_firmware
|
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.
|
CWE-287
Improper Authentication
|
CVE-2018-15556
|
2024-11-21 12:51 |
2019-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247512
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000…
|
CWE-20
Improper Input Validation
|
CVE-2018-15735
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247513
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000…
|
CWE-20
Improper Input Validation
|
CVE-2018-15734
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247514
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a NULL Pointer Dereference vulnerability due to not validating the size of the output buffer value from …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-15733
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247515
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not validating the output buffer address value from IOCtl 0x8000…
|
CWE-20
Improper Input Validation
|
CVE-2018-15732
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247516
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x800…
|
CWE-20
Improper Input Validation
|
CVE-2018-15731
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247517
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x800…
|
CWE-20
Improper Input Validation
|
CVE-2018-15730
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247518
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x800…
|
CWE-20
Improper Input Validation
|
CVE-2018-15729
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247519
|
5.3 |
MEDIUM
Network
|
cloudera
|
data_science_workbench
|
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts.
|
CWE-200
Information Exposure
|
CVE-2018-15665
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247520
|
9.8 |
CRITICAL
Network
|
chronoscan
|
chronoscan
|
SQL injection vulnerability in ChronoScan version 1.5.4.3 and earlier allows an unauthenticated attacker to execute arbitrary SQL commands via the wcr_machineid cookie.
|
CWE-89
SQL Injection
|
CVE-2018-15868
|
2024-11-21 12:51 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|