|
246071
|
9.8 |
CRITICAL
Network
|
elastic
|
kibana
|
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plainte…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-17245
|
2024-11-21 12:54 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246072
|
6.5 |
MEDIUM
Network
|
elastic
|
elasticsearch
|
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, LDAP, Native, or File realms. A request may receive…
|
CWE-200
Information Exposure
|
CVE-2018-17244
|
2024-11-21 12:54 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246073
|
6.1 |
MEDIUM
Network
|
apache
|
nifi
|
The message-page.jsp error page used the value of the HTTP request header X-ProxyContextPath without sanitization, resulting in a reflected XSS attack. Mitigation: The fix to correctly parse and sani…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17193
|
2024-11-21 12:54 |
2018-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246074
|
6.5 |
MEDIUM
Network
|
apache
|
nifi
|
The X-Frame-Options headers were applied inconsistently on some HTTP responses, resulting in duplicate or missing security headers. Some browsers would interpret these results incorrectly, allowing c…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2018-17192
|
2024-11-21 12:54 |
2018-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246075
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack …
|
CWE-319 CWE-863
Cleartext Transmission of Sensitive Information Incorrect Authorization
|
CVE-2018-17195
|
2024-11-21 12:54 |
2018-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246076
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
When a client request to a cluster node was replicated to other nodes in the cluster for verification, the Content-Length was forwarded. On a DELETE request, the body was ignored, but if the initial …
|
CWE-20
Improper Input Validation
|
CVE-2018-17194
|
2024-11-21 12:54 |
2018-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246077
|
9.8 |
CRITICAL
Network
|
dlink
|
dva-5592_firmware
|
An issue was discovered on D-Link DVA-5592 A1_WI_20180823 devices. If the PIN of the page "/ui/cbpc/login" is the default Parental Control PIN (0000), it is possible to bypass the login form by editi…
|
CWE-287
Improper Authentication
|
CVE-2018-17777
|
2024-11-21 12:54 |
2018-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246078
|
8.8 |
HIGH
Network
|
google redhat debian
|
chrome linux_desktop linux_workstation linux_server debian_linux
|
Incorrect object lifecycle handling in PDFium in Google Chrome prior to 71.0.3578.98 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2018-17481
|
2024-11-21 12:54 |
2018-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246079
|
4.8 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
Persistent cross-site scripting (XSS) vulnerability in Umbraco CMS 7.12.3 allows authenticated users to inject arbitrary web script via the Header Name of a content (Blog, Content Page, etc.). The vu…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17256
|
2024-11-21 12:54 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246080
|
9.8 |
CRITICAL
Network
|
apache
|
spark
|
In all versions of Apache Spark, its standalone resource manager accepts code to execute on a 'master' host, that then runs that code on 'worker' hosts. The master itself does not, by design, execute…
|
NVD-CWE-noinfo
|
CVE-2018-17190
|
2024-11-21 12:54 |
2018-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|