|
245971
|
6.5 |
MEDIUM
Network
|
apache
|
nifi
|
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing c…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2018-17192
|
2024-11-21 12:54 |
2018-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245972
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack …
|
CWE-319 CWE-863
Cleartext Transmission of Sensitive Information Incorrect Authorization
|
CVE-2018-17195
|
2024-11-21 12:54 |
2018-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245973
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial …
|
CWE-20
Improper Input Validation
|
CVE-2018-17194
|
2024-11-21 12:54 |
2018-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245974
|
9.8 |
CRITICAL
Network
|
dlink
|
dva-5592_firmware
|
An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000), it is possible to bypass the login form by editi…
|
CWE-287
Improper Authentication
|
CVE-2018-17777
|
2024-11-21 12:54 |
2018-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245975
|
8.8 |
HIGH
Network
|
google redhat debian
|
chrome linux_desktop linux_workstation linux_server debian_linux
|
Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2018-17481
|
2024-11-21 12:54 |
2018-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245976
|
4.8 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary web script via the Header Name of a content (Blog, Content Page, etc.). The vu…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17256
|
2024-11-21 12:54 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245977
|
9.8 |
CRITICAL
Network
|
apache
|
spark
|
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute…
|
NVD-CWE-noinfo
|
CVE-2018-17190
|
2024-11-21 12:54 |
2018-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245978
|
4.3 |
MEDIUM
Network
|
google redhat debian
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Incorrect dialog placement in Extensions in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of extension popups via a crafted HTML page.
|
NVD-CWE-noinfo
|
CVE-2018-17477
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245979
|
4.3 |
MEDIUM
Network
|
google redhat debian
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Incorrect dialog placement in Cast UI in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to obscure the full screen warning via a crafted HTML page.
|
NVD-CWE-noinfo
|
CVE-2018-17476
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245980
|
4.3 |
MEDIUM
Network
|
google redhat debian
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux
|
Incorrect handling of history on iOS in Navigation in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
|
NVD-CWE-noinfo
|
CVE-2018-17475
|
2024-11-21 12:54 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|