|
247681
|
7.5 |
HIGH
Network
|
canonical debian xmlsoft
|
ubuntu_linux debian_linux libxml2
|
A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case.…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-14404
|
2024-11-21 12:49 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247682
|
9.8 |
CRITICAL
Network
|
techsmith
|
mp4v2
|
MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-14403
|
2024-11-21 12:49 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247683
|
9.8 |
CRITICAL
Network
|
greenpacket
|
dv-360_firmware
|
Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to the HTTPS port, because lighttpd listens on all net…
|
CWE-77
Command Injection
|
CVE-2018-14067
|
2024-11-21 12:48 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247684
|
8.1 |
HIGH
Network
|
qualcomm
|
apq8053_firmware mdm9205_firmware mdm9206_firmware msm8909w_firmware msm8917_firmware msm8920_firmware msm8937_firmware msm8940_firmware msm8953_firmware sdm450_firmware
|
u'Error in UE due to race condition in EPCO handling' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, M…
|
CWE-362 CWE-476
Race Condition NULL Pointer Dereference
|
CVE-2018-13903
|
2024-11-21 12:48 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247685
|
4.8 |
MEDIUM
Network
|
seopanel
|
seo_panel
|
The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2018-14384
|
2024-11-21 12:48 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247686
|
7.8 |
HIGH
Local
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8053_firmware apq8096_firmware apq8096au_firmware apq8098_firmware ipq8074_firmware mdm9150_firmware mdm9206_firmware mdm9607_firmware<…
|
Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Sn…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-13916
|
2024-11-21 12:48 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247687
|
9.1 |
CRITICAL
Network
|
cospas-sarsat
|
cospas-sarsat_system
|
The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private messages (unrelated to distress alerts) via a craf…
|
CWE-310
Cryptographic Issues
|
CVE-2018-14062
|
2024-11-21 12:48 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247688
|
6.5 |
MEDIUM
Adjacent
|
arista
|
eos
|
Arista EOS through 4.21.0F allows a crash because 802.1x authentication is mishandled.
|
CWE-287
Improper Authentication
|
CVE-2018-14008
|
2024-11-21 12:48 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247689
|
7.5 |
HIGH
Network
|
ttpsc
|
the_scheduler
|
The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the versions 5.2.1 and 3.3.7
|
CWE-611
XXE
|
CVE-2018-14383
|
2024-11-21 12:48 |
2019-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247690
|
7.5 |
HIGH
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware qcs605_firmware sd_210_firmware sd_212_firmware sd_205_firmware …
|
Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Indu…
|
CWE-200
Information Exposure
|
CVE-2018-13897
|
2024-11-21 12:48 |
2019-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|