|
247691
|
8.1 |
HIGH
Network
|
mystrom
|
wifi_switch_firmware wifi_button_plus_firmware wifi_button_firmware wifi_switch_eu_firmware wifi_bulb_firmware wifi_led_strip_firmware
|
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and …
|
CWE-287
Improper Authentication
|
CVE-2018-15478
|
2024-11-21 12:50 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247692
|
8.1 |
HIGH
Network
|
mystrom
|
wifi_switch_firmware wifi_button_plus_firmware wifi_button_firmware wifi_switch_eu_firmware wifi_bulb_firmware wifi_led_strip_firmware
|
An issue was discovered in myStrom WiFi Switch V1 before 2.66, WiFi Switch V2 before 3.80, WiFi Switch EU before 3.80, WiFi Bulb before 2.58, WiFi LED Strip before 3.80, WiFi Button before 2.73, and …
|
CWE-295
Improper Certificate Validation
|
CVE-2018-15476
|
2024-11-21 12:50 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247693
|
7.5 |
HIGH
Network
|
epson
|
iprint
|
The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-14901
|
2024-11-21 12:50 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247694
|
7.5 |
HIGH
Network
|
epson
|
wf-2750_firmware
|
On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. Remote attackers can send print jobs directly to the printer via TCP port 9100.
|
CWE-417
Channel and Path Errors
|
CVE-2018-14900
|
2024-11-21 12:50 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247695
|
6.1 |
MEDIUM
Network
|
epson
|
wf-2750_firmware
|
On the EPSON WF-2750 printer with firmware JP02I2, the Web interface AirPrint Setup page is vulnerable to HTML Injection that can redirect users to malicious sites.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14899
|
2024-11-21 12:50 |
2018-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247696
|
8.8 |
HIGH
Network
|
auth0
|
aspnet-owin aspnet
|
An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 and OpenID Connect protocols. This leaves applicatio…
|
CWE-352
Origin Validation Error
|
CVE-2018-15121
|
2024-11-21 12:50 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247697
|
4.7 |
MEDIUM
Local
|
gearsoftware
|
gearaspiwdm
|
GEAR Software products that include GEARAspiWDM.sys, 2.2.5.0, allow local users to cause a denial of service (Race Condition and BSoD on Windows) by not checking that user-mode memory is available ri…
|
CWE-362
Race Condition
|
CVE-2018-15499
|
2024-11-21 12:50 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247698
|
6.5 |
MEDIUM
Network
|
gnome canonical
|
pango ubuntu_linux
|
libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15120
|
2024-11-21 12:50 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247699
|
8.8 |
HIGH
Network
|
ucopia
|
wireless_appliance_firmware
|
Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices using firmware version 5.1.x before 5.1.13 allows authenticated remote attackers to escape …
|
CWE-78
OS Command
|
CVE-2018-15481
|
2024-11-21 12:50 |
2018-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247700
|
7.5 |
HIGH
Network
|
embedthis juniper
|
appweb goahead junos
|
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus caus…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-15505
|
2024-11-21 12:50 |
2018-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|