|
246001
|
4.9 |
MEDIUM
Network
|
openvswitch redhat canonical debian
|
openvswitch openstack ubuntu_linux debian_linux
|
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17206
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246002
|
7.5 |
HIGH
Network
|
openvswitch redhat canonical
|
openvswitch openstack ubuntu_linux
|
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto …
|
CWE-617
Reachable Assertion
|
CVE-2018-17205
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246003
|
4.3 |
MEDIUM
Network
|
openvswitch redhat canonical debian
|
openvswitch openstack ubuntu_linux debian_linux
|
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and comman…
|
CWE-617
Reachable Assertion
|
CVE-2018-17204
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246004
|
7.8 |
HIGH
Local
|
debian canonical artifex redhat
|
debian_linux ubuntu_linux ghostscript enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus ent…
|
Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error hand…
|
NVD-CWE-noinfo
|
CVE-2018-17183
|
2024-11-21 12:54 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246005
|
7.8 |
HIGH
Local
|
linux canonical debian netapp
|
linux_kernel ubuntu_linux debian_linux element_software active_iq_performance_analytics_services
|
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possib…
|
CWE-416
Use After Free
|
CVE-2018-17182
|
2024-11-21 12:54 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246006
|
5.3 |
MEDIUM
Adjacent
|
neatorobotics
|
botvac_d4_connected_firmware botvac_d6_connected_firmware botvac_d5_connected_firmware botvac_d7_connected_firmware botvac_d3_connected_firmware
|
An issue was discovered on Neato Botvac Connected 2.2.0 devices. They execute unauthenticated manual drive commands (sent to /bin/webserver on port 8081) if they already have an active session. Comma…
|
NVD-CWE-noinfo
|
CVE-2018-17178
|
2024-11-21 12:54 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246007
|
2.4 |
LOW
Physics
|
neatorobotics
|
botvac_d4_connected_firmware botvac_d6_connected_firmware botvac_d5_connected_firmware botvac_d7_connected_firmware botvac_d3_connected_firmware botvac_85_firmware
|
An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2018-17177
|
2024-11-21 12:54 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246008
|
7.5 |
HIGH
Network
|
neatorobotics
|
botvac_d4_connected_firmware botvac_d6_connected_firmware botvac_d7_connected_firmware
|
A replay issue was discovered on Neato Botvac Connected 2.2.0 devices. Manual control mode requires authentication, but once recorded, the authentication (always transmitted in cleartext) can be repl…
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2018-17176
|
2024-11-21 12:54 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246009
|
5.3 |
MEDIUM
Network
|
marshmallow_project
|
marshmallow
|
In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to exp…
|
NVD-CWE-noinfo
|
CVE-2018-17175
|
2024-11-21 12:54 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246010
|
8.8 |
HIGH
Network
|
abus
|
tvip_10000_firmware tvip_10001_firmware tvip_10005_firmware tvip_10005a_firmware tvip_10005b_firmware tvip_10050_firmware tvip_10051_firmware tvip_10055a_firmware tvip_10055b_…
|
An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, and thus execute code arbitrarily with root privileges.
|
CWE-22
Path Traversal
|
CVE-2018-16739
|
2024-11-21 12:53 |
2023-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|