|
247441
|
7.5 |
HIGH
Network
|
leagoo
|
z5c_firmware
|
The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.m…
|
CWE-200
Information Exposure
|
CVE-2018-14984
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247442
|
4.7 |
MEDIUM
Local
|
asus
|
zenfone_3_max_firmware
|
The ASUS ZenFone 3 Max Android device with a build fingerprint of asus/US_Phone/ASUS_X008_1:7.0/NRD90M/US_Phone-14.14.1711.92-20171208:user/release-keys contains a pre-installed app with a package na…
|
CWE-200
Information Exposure
|
CVE-2018-14979
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247443
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
When APM 13.0.0-13.1.x is deployed as an OAuth Resource Server, APM becomes a client application to an external OAuth authorization server. In certain cases when communication between the BIG-IP APM …
|
NVD-CWE-noinfo
|
CVE-2018-15335
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247444
|
4.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
A cross-site request forgery (CSRF) vulnerability in the APM webtop 11.2.1 or greater may allow attacker to force an APM webtop session to log out and require re-authentication.
|
CWE-352
Origin Validation Error
|
CVE-2018-15334
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247445
|
5.5 |
MEDIUM
Local
|
f5
|
big-ip_local_traffic_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_analytics big-ip_access_policy_manager big-ip_domain_name_system big-ip_…
|
On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user with any role, including Guest Role, to have access and download previously generated and available snap…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-15333
|
2024-11-21 12:50 |
2018-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247446
|
8.8 |
HIGH
Network
|
qt debian opensuse
|
qt debian_linux leap
|
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
|
CWE-415
Double Free
|
CVE-2018-15518
|
2024-11-21 12:50 |
2018-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247447
|
8.1 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_software
|
A vulnerability in the authorization subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, but unprivileged (levels 0 and 1), remote attacker to perform privileg…
|
CWE-863
Incorrect Authorization
|
CVE-2018-15465
|
2024-11-21 12:50 |
2018-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247448
|
7.8 |
HIGH
Local
|
f5
|
big-ip_application_acceleration_manager
|
On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, which could be used to leverage attacks against the…
|
CWE-269
Improper Privilege Management
|
CVE-2018-15331
|
2024-11-21 12:50 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247449
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to process a gzip bomb as a payload, the BIG-IP system will experience a fatal er…
|
CWE-20
Improper Input Validation
|
CVE-2018-15330
|
2024-11-21 12:50 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247450
|
7.2 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also…
|
CWE-862
Missing Authorization
|
CVE-2018-15329
|
2024-11-21 12:50 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|