|
249221
|
6.1 |
MEDIUM
Network
|
seagate
|
nas_os
|
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12297
|
2024-11-21 12:44 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249222
|
7.5 |
HIGH
Network
|
seagate
|
nas_os
|
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-12296
|
2024-11-21 12:44 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249223
|
9.8 |
CRITICAL
Network
|
seagate
|
nas_os
|
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.
|
CWE-89
SQL Injection
|
CVE-2018-12295
|
2024-11-21 12:44 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249224
|
6.3 |
MEDIUM
Network
|
symantec
|
endpoint_protection
|
SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a CSV/DDE injection (also known as formula injection) vulnerability, which is a type of issue whereby …
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2018-12244
|
2024-11-21 12:44 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249225
|
5.5 |
MEDIUM
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware qcs605_firmware sd_410_firmware sd_412_firmware sd_615_firmware sd_616_firmware sd_415_firmware sd_63…
|
Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asset leakage in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electroni…
|
CWE-200
Information Exposure
|
CVE-2018-11971
|
2024-11-21 12:44 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249226
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware qcs605_firmware sd_410_firmware sd_412_firmware sd_636_firmware sd_712_firmware sd_710_firmware sd_67…
|
TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snap…
|
NVD-CWE-noinfo
|
CVE-2018-11970
|
2024-11-21 12:44 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249227
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9150_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware mdm9655_firmware msm8909w_firmware msm8996au_firmware qcs605_firmware sd_210_firmware
|
Undefined behavior in UE while processing unknown IEI in OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearable…
|
CWE-20
Improper Input Validation
|
CVE-2018-11966
|
2024-11-21 12:44 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249228
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_410_firmware sd_412_firmware sd_820a_firmware
|
Improper input validation in QCPE create function may lead to integer overflow in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile in MDM920…
|
CWE-20
Improper Input Validation
|
CVE-2018-11830
|
2024-11-21 12:44 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249229
|
5.5 |
MEDIUM
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware mdm9655_firmware qm215_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware sd_412_firmware sd_425…
|
Insufficient protection of keys in keypad can lead HLOS to gain access to confidential keypad input data in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Sna…
|
NVD-CWE-noinfo
|
CVE-2018-11958
|
2024-11-21 12:44 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249230
|
6.8 |
MEDIUM
Physics
|
tianocore
|
edk_ii
|
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12183
|
2024-11-21 12:44 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|