|
249131
|
8.1 |
HIGH
Network
|
ecos
|
secure_boot_stick_firmware
|
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via compromised firmware.
|
NVD-CWE-noinfo
|
CVE-2018-12330
|
2024-11-21 12:45 |
2018-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249132
|
5.9 |
MEDIUM
Network
|
ecos
|
secure_boot_stick_firmware
|
Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.
|
CWE-200
Information Exposure
|
CVE-2018-12329
|
2024-11-21 12:45 |
2018-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249133
|
7.5 |
HIGH
Network
|
1000guess
|
1000_guess
|
The _addguess function of a simplelottery smart contract implementation for 1000 Guess, an Ethereum gambling game, generates a random value with publicly readable variables such as the current block …
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2018-12454
|
2024-11-21 12:45 |
2018-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249134
|
7.5 |
HIGH
Network
|
redislabs
|
redis
|
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a strea…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-12453
|
2024-11-21 12:45 |
2018-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249135
|
7.5 |
HIGH
Network
|
tinyexr_project
|
tinyexr
|
tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h.
|
CWE-617
Reachable Assertion
|
CVE-2018-12504
|
2024-11-21 12:45 |
2018-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249136
|
9.8 |
CRITICAL
Network
|
tinyexr_project
|
tinyexr
|
tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-12503
|
2024-11-21 12:45 |
2018-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249137
|
6.1 |
MEDIUM
Network
|
nagios
|
fusion
|
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12501
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249138
|
9.8 |
CRITICAL
Network
|
icmsdev
|
icms
|
spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.
|
CWE-89
SQL Injection
|
CVE-2018-12498
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249139
|
5.5 |
MEDIUM
Local
|
discount_project debian
|
discount debian_linux
|
The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-12495
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249140
|
6.5 |
MEDIUM
Network
|
publiccms
|
publiccms
|
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate/content.html?path=../ URI.
|
CWE-22
Path Traversal
|
CVE-2018-12494
|
2024-11-21 12:45 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|