|
249581
|
4.7 |
MEDIUM
Local
|
wolfssl
|
wolfssl
|
wolfcrypt/src/ecc.c in wolfSSL before 3.15.1.patch allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the a…
|
CWE-200
Information Exposure
|
CVE-2018-12436
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249582
|
5.9 |
MEDIUM
Local
|
botan_project
|
botan
|
Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP, related to dsa/dsa.cpp, ec_group/ec_group.c…
|
CWE-200
Information Exposure
|
CVE-2018-12435
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249583
|
4.7 |
MEDIUM
Local
|
openbsd
|
libressl
|
LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attack…
|
CWE-200
Information Exposure
|
CVE-2018-12434
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249584
|
4.9 |
MEDIUM
Physics
|
cryptlib
|
cryptlib
|
cryptlib through 3.4.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to eit…
|
CWE-200 CWE-320
Information Exposure Key Management Errors
|
CVE-2018-12433
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249585
|
6.1 |
MEDIUM
Network
|
javamelody_project
|
javamelody
|
JavaMelody through 1.60.0 has XSS via the counter parameter in a clear_counter action to the /monitoring URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12432
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249586
|
4.8 |
MEDIUM
Network
|
seacms
|
seacms
|
SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page).
|
CWE-79
Cross-site Scripting
|
CVE-2018-12431
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249587
|
9.8 |
CRITICAL
Network
|
simple_password_store_project
|
simple_password_store
|
An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-12356
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249588
|
7.5 |
HIGH
Network
|
matrix
|
synapse
|
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
|
NVD-CWE-noinfo
|
CVE-2018-12423
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249589
|
7.5 |
HIGH
Network
|
icehrm
|
icehrm
|
IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-12420
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249590
|
9.8 |
CRITICAL
Network
|
ltb-project
|
ldap_tool_box_self_service_password
|
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishan…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2018-12421
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|