|
246351
|
9.8 |
CRITICAL
Network
|
x.org debian canonical
|
libx11 debian_linux ubuntu_linux
|
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c interprets a variable as signed instead of unsigned, resulting in an out-of-bounds write (of up to 128 bytes…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14600
|
2024-11-21 12:49 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246352
|
9.8 |
CRITICAL
Network
|
x.org debian canonical fedoraproject redhat
|
libx11 debian_linux ubuntu_linux fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspec…
|
CWE-193
Off-by-one Error
|
CVE-2018-14599
|
2024-11-21 12:49 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246353
|
7.5 |
HIGH
Network
|
x.org debian canonical fedoraproject
|
libx11 debian_linux ubuntu_linux fedora
|
An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that wil…
|
CWE-20
Improper Input Validation
|
CVE-2018-14598
|
2024-11-21 12:49 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246354
|
7.8 |
HIGH
Local
|
emerson
|
deltav
|
Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which may allow arbitrary co…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2018-14797
|
2024-11-21 12:49 |
2018-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246355
|
7.8 |
HIGH
Local
|
emerson
|
deltav
|
Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 may allow non-administrative users to change executable and library files on the affected products.
|
CWE-269
Improper Privilege Management
|
CVE-2018-14791
|
2024-11-21 12:49 |
2018-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246356
|
9.4 |
CRITICAL
Network
|
bd
|
alaris_gs_firmware alaris_gh_firmware alaris_cc_firmware alaris_tiva_firmware
|
Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and prior are affected by an improper authentication vuln…
|
CWE-287
Improper Authentication
|
CVE-2018-14786
|
2024-11-21 12:49 |
2018-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246357
|
6.2 |
MEDIUM
Physics
|
philips
|
pagewriter_tc70_firmware pagewriter_tc50_firmware pagewriter_tc30_firmware pagewriter_tc20_firmware pagewriter_tc10_firmware
|
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-14801
|
2024-11-21 12:49 |
2018-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246358
|
3.7 |
LOW
Physics
|
philips
|
pagewriter_tc70_firmware pagewriter_tc50_firmware pagewriter_tc30_firmware pagewriter_tc20_firmware pagewriter_tc10_firmware
|
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or form…
|
CWE-119 CWE-134
Incorrect Access of Indexable Resource ('Range Error') Use of Externally-Controlled Format String
|
CVE-2018-14799
|
2024-11-21 12:49 |
2018-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246359
|
6.7 |
MEDIUM
Local
|
philips
|
xcelera intellispace_cardiovascular
|
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an unquoted search path or element vulnerability has been identified, which may a…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2018-14789
|
2024-11-21 12:49 |
2018-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246360
|
7.8 |
HIGH
Local
|
philips
|
xcelera intellispace_cardiovascular
|
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalated privileges could access folders which contain executab…
|
CWE-269
Improper Privilege Management
|
CVE-2018-14787
|
2024-11-21 12:49 |
2018-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|