|
247511
|
9.8 |
CRITICAL
Network
|
spirton
|
universal_media_server
|
In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use th…
|
CWE-611
XXE
|
CVE-2018-13416
|
2024-11-21 12:47 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247512
|
8.1 |
HIGH
Network
|
atlassian
|
sourcetree
|
There was an argument injection vulnerability in Sourcetree for Windows via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree f…
|
CWE-88
Argument Injection
|
CVE-2018-13386
|
2024-11-21 12:47 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247513
|
9.8 |
CRITICAL
Network
|
atlassian
|
sourcetree
|
There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for…
|
CWE-88
Argument Injection
|
CVE-2018-13385
|
2024-11-21 12:47 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247514
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira jira_server
|
The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9…
|
CWE-79
Cross-site Scripting
|
CVE-2018-13387
|
2024-11-21 12:47 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247515
|
5.5 |
MEDIUM
Local
|
nagios
|
nagios_core
|
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-13458
|
2024-11-21 12:47 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247516
|
5.5 |
MEDIUM
Local
|
nagios
|
nagios_core
|
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-13457
|
2024-11-21 12:47 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247517
|
5.5 |
MEDIUM
Local
|
nagios
|
nagios
|
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-13441
|
2024-11-21 12:47 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247518
|
4.7 |
MEDIUM
Network
|
atlassian
|
confluence
|
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of applic…
|
CWE-20
Improper Input Validation
|
CVE-2018-13389
|
2024-11-21 12:47 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247519
|
5.4 |
MEDIUM
Network
|
atlassian
|
fisheye crucible
|
The review attachment resource in Atlassian Fisheye and Crucible before version 4.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in …
|
CWE-79
Cross-site Scripting
|
CVE-2018-13388
|
2024-11-21 12:47 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247520
|
6.7 |
MEDIUM
Local
|
supermicro
|
x11ssz_firmware x11ssv_firmware x11ssql_firmware x11ssq_firmware x11ssn_firmware x11srm_firmware x11sra_firmware x11sba_firmware x11sat_firmware x11sae_m_firmware x11sae…
|
Certain Supermicro X11S, X10, X9, X8SI, K1SP, C9X299, C7, B1, A2, and A1 products have a misconfigured Descriptor Region, allowing OS programs to modify firmware.
|
NVD-CWE-noinfo
|
CVE-2018-13787
|
2024-11-21 12:47 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|