|
247771
|
8.8 |
HIGH
Network
|
avaya
|
ip_office
|
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 th…
|
CWE-22
Path Traversal
|
CVE-2018-15610
|
2024-11-21 12:51 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247772
|
5.5 |
MEDIUM
Local
|
radare
|
radare2
|
In radare2 before 2.9.0, a heap overflow vulnerability exists in the read_module_referenced_functions function in libr/anal/flirt.c via a crafted flirt signature file.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-15834
|
2024-11-21 12:51 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247773
|
5.9 |
MEDIUM
Network
|
subsonic
|
music_streamer
|
The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man-in-the-middle attackers to obtain interaction dat…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-15898
|
2024-11-21 12:51 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247774
|
7.2 |
HIGH
Network
|
monstra
|
monstra
|
Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippet&filename=google-analytics URI, which allows attackers to …
|
CWE-94
Code Injection
|
CVE-2018-15886
|
2024-11-21 12:51 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247775
|
7.5 |
HIGH
Network
|
theethereumlottery
|
the_ethereum_lottery
|
The "PayWinner" function of a simplelottery smart contract implementation for The Ethereum Lottery, an Ethereum gambling game, generates a random value with publicly readable variable "maxTickets" (w…
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2018-15552
|
2024-11-21 12:51 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247776
|
7.8 |
HIGH
Local
|
pulsesecure
|
pulse_secure_desktop_client
|
The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability.
|
NVD-CWE-noinfo
|
CVE-2018-15865
|
2024-11-21 12:51 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247777
|
5.5 |
MEDIUM
Local
|
pulsesecure
|
pulse_secure_desktop_client
|
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Format String Vulnerability.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2018-15749
|
2024-11-21 12:51 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247778
|
5.3 |
MEDIUM
Local
|
pulsesecure
|
pulse_secure_desktop_client
|
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability.
|
CWE-78
OS Command
|
CVE-2018-15726
|
2024-11-21 12:51 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247779
|
5.4 |
MEDIUM
Network
|
jorani_project
|
jorani
|
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the applic…
|
CWE-89
SQL Injection
|
CVE-2018-15918
|
2024-11-21 12:51 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247780
|
5.4 |
MEDIUM
Network
|
jorani_project
|
jorani
|
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15917
|
2024-11-21 12:51 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|