|
246371
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x800…
|
CWE-20
Improper Input Validation
|
CVE-2018-15730
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246372
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x800…
|
CWE-20
Improper Input Validation
|
CVE-2018-15729
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246373
|
5.3 |
MEDIUM
Network
|
cloudera
|
data_science_workbench
|
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts.
|
CWE-200
Information Exposure
|
CVE-2018-15665
|
2024-11-21 12:51 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246374
|
9.8 |
CRITICAL
Network
|
chronoscan
|
chronoscan
|
SQL injection vulnerability in ChronoScan version 1.5.4.3 and earlier allows an unauthenticated attacker to execute arbitrary SQL commands via the wcr_machineid cookie.
|
CWE-89
SQL Injection
|
CVE-2018-15868
|
2024-11-21 12:51 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246375
|
9.8 |
CRITICAL
Network
|
glot
|
glot-www
|
The default configuration of glot-www through 2018-05-19 allows remote attackers to execute arbitrary code because glot-code-runner supports os.system within a "python" "files" "content" JSON file.
|
CWE-20
Improper Input Validation
|
CVE-2018-15747
|
2024-11-21 12:51 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246376
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x800…
|
CWE-20
Improper Input Validation
|
CVE-2018-15737
|
2024-11-21 12:51 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246377
|
5.5 |
MEDIUM
Local
|
stopzilla
|
antimalware
|
An issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to not validating the output buffer address value from IOCtl 0x800…
|
CWE-20
Improper Input Validation
|
CVE-2018-15736
|
2024-11-21 12:51 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246378
|
6.1 |
MEDIUM
Network
|
cloudera
|
cloudera_manager
|
An issue was discovered in Cloudera Manager 5.x through 5.15.0. One type of page in Cloudera Manager uses a 'returnUrl' parameter to redirect the user to another page in Cloudera Manager once a wizar…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15913
|
2024-11-21 12:51 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246379
|
4.3 |
MEDIUM
Network
|
freepbx
|
disa
|
FreePBX 13 and 14 has SQL Injection in the DISA module via the hangup variable on the /admin/config.php?display=disa&view=form page.
|
CWE-89
SQL Injection
|
CVE-2018-15892
|
2024-11-21 12:51 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246380
|
4.8 |
MEDIUM
Network
|
freepbx sangoma
|
freepbx
|
An issue was discovered in FreePBX core before 3.0.122.43, 14.0.18.34, and 5.0.1beta4. By crafting a request for adding Asterisk modules, an attacker is able to store JavaScript commands in a module …
|
CWE-79
Cross-site Scripting
|
CVE-2018-15891
|
2024-11-21 12:51 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|