|
249721
|
7.2 |
HIGH
Network
|
symantec
|
reporter
|
The Symantec Reporter CLI 10.1 prior to 10.1.5.6 and 10.2 prior to 10.2.1.8 is susceptible to an OS command injection vulnerability. An authenticated malicious administrator with Enable mode access c…
|
CWE-78
OS Command
|
CVE-2018-12237
|
2024-11-21 12:44 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249722
|
8.8 |
HIGH
Adjacent
|
qualcomm
|
mdm9206_firmware mdm9607_firmware
|
Improper check while accessing the local memory stack on MQTT connection request can lead to buffer overflow in snapdragon wear in versions MDM9206, MDM9607
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11993
|
2024-11-21 12:44 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249723
|
5.5 |
MEDIUM
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9635m_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_410_firmware …
|
Improper input validation in trustzone can lead to denial of service in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996A…
|
CWE-20
Improper Input Validation
|
CVE-2018-11999
|
2024-11-21 12:44 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249724
|
7.5 |
HIGH
Adjacent
|
qualcomm
|
mdm9206_firmware mdm9607_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_427_firmware sd_435_firmware sd_450_firmware sd_625_firmware sd_636_firmware sd_835_…
|
While processing a packet decode request in MQTT, Race condition can occur leading to an out-of-bounds access in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, SD 210/SD 212/SD 2…
|
CWE-362
Race Condition
|
CVE-2018-11998
|
2024-11-21 12:44 |
2019-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249725
|
7.8 |
HIGH
Local
|
intel
|
proset\/wireless_software
|
Improper directory permissions in the ZeroConfig service in Intel(R) PROSet/Wireless WiFi Software before version 20.90.0.7 may allow an authorized user to potentially enable escalation of privilege …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-12177
|
2024-11-21 12:44 |
2019-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249726
|
4.4 |
MEDIUM
Local
|
intel
|
optane_ssd_dc_p4800x_firmware
|
Firmware update routine in bootloader for Intel(R) Optane(TM) SSD DC P4800X before version E2010435 may allow a privileged user to potentially enable a denial of service via local access.
|
CWE-20
Improper Input Validation
|
CVE-2018-12167
|
2024-11-21 12:44 |
2019-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249727
|
4.4 |
MEDIUM
Local
|
intel
|
optane_ssd_dc_p4800x_firmware
|
Insufficient write protection in firmware for Intel(R) Optane(TM) SSD DC P4800X before version E2010435 may allow a privileged user to potentially enable a denial of service via local access.
|
CWE-20
Improper Input Validation
|
CVE-2018-12166
|
2024-11-21 12:44 |
2019-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249728
|
6.5 |
MEDIUM
Network
|
apache
|
thrift
|
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside th…
|
CWE-538
File and Directory Information Exposure
|
CVE-2018-11798
|
2024-11-21 12:44 |
2019-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249729
|
9.8 |
CRITICAL
Network
|
apache
|
karaf
|
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The features XML is parsed by XMLInputFactory class. A…
|
CWE-611
XXE
|
CVE-2018-11788
|
2024-11-21 12:44 |
2019-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249730
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Un-trusted pointer de-reference issue by accessing a variable which is already freed.
|
CWE-416
Use After Free
|
CVE-2018-11988
|
2024-11-21 12:44 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|