|
249101
|
8.8 |
HIGH
Network
|
apache
|
hadoop
|
In Apache Hadoop 2.7.4 to 2.7.6, the security fix for CVE-2016-6811 is incomplete. A user who can escalate to yarn user can possibly run arbitrary commands as root user.
|
NVD-CWE-noinfo
|
CVE-2018-11766
|
2024-11-21 12:43 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249102
|
7.5 |
HIGH
Network
|
apache debian redhat
|
tomcat_jk_connector debian_linux jboss_core_services
|
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge…
|
CWE-22
Path Traversal
|
CVE-2018-11759
|
2024-11-21 12:43 |
2018-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249103
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware …
|
When a series of FDAL messages are sent to the modem, a Use After Free condition can occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9640, MDM9650, …
|
CWE-416
Use After Free
|
CVE-2018-11305
|
2024-11-21 12:43 |
2018-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249104
|
5.5 |
MEDIUM
Local
|
puppet
|
cisco_ios
|
Previous releases of the Puppet cisco_ios module output SSH session debug information including login credentials to a world readable file on every run. These issues have been resolved in the 0.4.0 r…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-11752
|
2024-11-21 12:43 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249105
|
6.5 |
MEDIUM
Network
|
puppet
|
cisco_ios_module
|
Previous releases of the Puppet cisco_ios module did not validate a host's identity before starting a SSH connection. As of the 0.4.0 release of cisco_ios, host key checking is enabled by default.
|
CWE-20
Improper Input Validation
|
CVE-2018-11750
|
2024-11-21 12:43 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249106
|
7.8 |
HIGH
Local
|
puppet
|
device_manager
|
Previous releases of the Puppet device_manager module creates configuration files containing credentials that are world readable. This issue has been resolved as of device_manager 2.7.0.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-11748
|
2024-11-21 12:43 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249107
|
5.9 |
MEDIUM
Network
|
apache canonical redhat oracle netapp
|
http_server ubuntu_linux enterprise_linux retail_xstore_point_of_service hospitality_guest_access enterprise_manager_ops_center secure_global_desktop instantis_enterprisetrack
|
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This…
|
NVD-CWE-noinfo
|
CVE-2018-11763
|
2024-11-21 12:43 |
2018-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249108
|
8.8 |
HIGH
Network
|
samsung
|
samsung_members
|
This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Samsung Members Fixed in version 2.4.25. An attacker must first obtain the ability to execute low-priv…
|
NVD-CWE-noinfo
|
CVE-2018-11614
|
2024-11-21 12:43 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249109
|
4.0 |
MEDIUM
Network
|
wallabag
|
wallabag
|
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScr…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11352
|
2024-11-21 12:43 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249110
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware qca6574au_firmware qca6584_firmware sd210_firmware sd212_firmware
|
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCA6574AU, QCA6584, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 45…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2018-11292
|
2024-11-21 12:43 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|