|
247001
|
7.1 |
HIGH
Local
|
expressvpn
|
expressvpn
|
An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication …
|
CWE-22
Path Traversal
|
CVE-2018-15490
|
2024-11-21 12:50 |
2019-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247002
|
7.8 |
HIGH
Local
|
skydevices
|
sky_elite_6.0l\+_firmware
|
The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482897127:user/release-keys contains a pre-installed platform app with a package n…
|
CWE-78
OS Command
|
CVE-2018-15007
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247003
|
5.5 |
MEDIUM
Local
|
zteusa
|
zte_zmax_champ_firmware
|
The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package name of com.androi…
|
NVD-CWE-noinfo
|
CVE-2018-15006
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247004
|
7.1 |
HIGH
Local
|
zteusa
|
zte_zmax_champ_firmware
|
The ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a pre-installed platform app with a package name of com.zte.zd…
|
NVD-CWE-noinfo CWE-862
Missing Authorization
|
CVE-2018-15005
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247005
|
5.9 |
MEDIUM
Network
|
coolpad
|
canvas_firmware
|
The Coolpad Canvas device with a build fingerprint of Coolpad/cp3636a/cp3636a:7.0/NRD90M/093031423:user/release-keys contains a platform app with a package name of com.qualcomm.qti.modemtestmode (ver…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-15004
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247006
|
4.7 |
MEDIUM
Local
|
vivo
|
v7_firmware
|
The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any app co-located on the device to set system properties as the com.android.phone u…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-15002
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247007
|
5.5 |
MEDIUM
Local
|
vivo
|
v7_firmware
|
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, ver…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-15001
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247008
|
6.8 |
MEDIUM
Physics
|
leagoo
|
p1_firmware
|
The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a hidden root privilege escalation capability to achieve …
|
CWE-78
OS Command
|
CVE-2018-14998
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247009
|
4.7 |
MEDIUM
Local
|
zteusa
|
zte_blade_vantage_firmware zte_blade_spark_firmware zte_zmax_pro_firmware zte_zmax_champ_firmware
|
The ZTE Blade Vantage Android device with a build fingerprint of ZTE/Z839/sweet:7.1.1/NMF26V/20180120.095344:user/release-keys, the ZTE Blade Spark Android device with a build fingerprint of ZTE/Z971…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-14995
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247010
|
5.5 |
MEDIUM
Local
|
asus
|
zenfone_3_max_firmware
|
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed platform app with a p…
|
NVD-CWE-noinfo
|
CVE-2018-14992
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|