|
246811
|
7.5 |
HIGH
Network
|
yandex
|
clickhouse
|
ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server.
|
CWE-200
Information Exposure
|
CVE-2018-14669
|
2024-11-21 12:49 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246812
|
8.8 |
HIGH
Network
|
yandex
|
clickhouse
|
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks.
|
CWE-352
Origin Validation Error
|
CVE-2018-14668
|
2024-11-21 12:49 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246813
|
4.9 |
MEDIUM
Network
|
damicms
|
damicms
|
An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI.
|
CWE-200
Information Exposure
|
CVE-2018-14831
|
2024-11-21 12:49 |
2019-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246814
|
9.8 |
CRITICAL
Network
|
vivotek
|
fd8136_firmware
|
Vivotek FD8136 devices allow remote memory corruption and remote code execution because of a stack-based buffer overflow, related to sprintf, vlocal_buff_4326, and set_getparam.cgi. NOTE: The vendor …
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14496
|
2024-11-21 12:49 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246815
|
9.8 |
CRITICAL
Network
|
vivotek
|
fd8136_firmware
|
Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as…
|
CWE-78
OS Command
|
CVE-2018-14495
|
2024-11-21 12:49 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246816
|
9.8 |
CRITICAL
Network
|
vivotek
|
fd8136_firmware
|
Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July …
|
CWE-78
OS Command
|
CVE-2018-14494
|
2024-11-21 12:49 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246817
|
8.8 |
HIGH
Network
|
libpng oracle netapp
|
libpng mysql_workbench hyperion_infrastructure_technology oncommand_api_services active_iq_unified_manager
|
An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-14550
|
2024-11-21 12:49 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246818
|
5.9 |
MEDIUM
Network
|
intuit
|
lacerte
|
Intuit Lacerte 2017 has Incorrect Access Control.
|
CWE-284
Improper Access Control
|
CVE-2018-14833
|
2024-11-21 12:49 |
2019-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246819
|
7.5 |
HIGH
Network
|
odoo
|
odoo
|
The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial of service) under certain circumstances.
|
CWE-20
Improper Input Validation
|
CVE-2018-14733
|
2024-11-21 12:49 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246820
|
7.5 |
HIGH
Network
|
invoxia
|
nvx220_firmware
|
Invoxia NVX220 devices allow access to /bin/sh via escape from a restricted CLI, leading to disclosure of password hashes.
|
CWE-200
Information Exposure
|
CVE-2018-14529
|
2024-11-21 12:49 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|