|
246141
|
7.5 |
HIGH
Network
|
libtirpc_project
|
libtirpc
|
An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than select, exhaustion of file descriptors would cause the server to enter an infini…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-14621
|
2024-11-21 12:49 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246142
|
7.5 |
HIGH
Network
|
redhat debian canonical libtirpc_project
|
enterprise_linux debian_linux ubuntu_linux enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_workstation enterprise_linux_desktop libtirpc
|
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the serve…
|
CWE-252
Unchecked Return Value
|
CVE-2018-14622
|
2024-11-21 12:49 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246143
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when each af_alg_ctx was freed instead of when the aead_tfm was free…
|
CWE-20
Improper Input Validation
|
CVE-2018-14619
|
2024-11-21 12:49 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246144
|
8.8 |
HIGH
Network
|
vivotek
|
camera
|
Various VIVOTEK FD8*, FD9*, FE9*, IB8*, IB9*, IP9*, IZ9*, MS9*, SD9*, and other devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code.
|
NVD-CWE-noinfo
|
CVE-2018-14768
|
2024-11-21 12:49 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246145
|
9.8 |
CRITICAL
Network
|
hitachienergy
|
esoms
|
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both cond…
|
CWE-287
Improper Authentication
|
CVE-2018-14805
|
2024-11-21 12:49 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246146
|
7.8 |
HIGH
Local
|
pyconuk
|
conference-scheduler-cli
|
In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.syste…
|
CWE-78 CWE-502
OS Command Deserialization of Untrusted Data
|
CVE-2018-14572
|
2024-11-21 12:49 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246147
|
9.8 |
CRITICAL
Network
|
x.org debian canonical
|
libx11 debian_linux ubuntu_linux
|
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14600
|
2024-11-21 12:49 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246148
|
9.8 |
CRITICAL
Network
|
x.org debian canonical fedoraproject redhat
|
libx11 debian_linux ubuntu_linux fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspec…
|
CWE-193
Off-by-one Error
|
CVE-2018-14599
|
2024-11-21 12:49 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246149
|
7.5 |
HIGH
Network
|
x.org debian canonical fedoraproject
|
libx11 debian_linux ubuntu_linux fedora
|
An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that wil…
|
CWE-20
Improper Input Validation
|
CVE-2018-14598
|
2024-11-21 12:49 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246150
|
7.8 |
HIGH
Local
|
emerson
|
deltav
|
Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which may allow arbitrary co…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2018-14797
|
2024-11-21 12:49 |
2018-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|