|
246941
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-816_a2_firmware
|
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/Diagnosis route. This could lead…
|
CWE-78
OS Command
|
CVE-2018-17068
|
2024-11-21 12:53 |
2018-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246942
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-816_a2_firmware
|
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow and overwrite the return address.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17067
|
2024-11-21 12:53 |
2018-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246943
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-816_a2_firmware
|
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This cou…
|
CWE-78
OS Command
|
CVE-2018-17066
|
2024-11-21 12:53 |
2018-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246944
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-816_a2_firmware
|
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite th…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17065
|
2024-11-21 12:53 |
2018-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246945
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-816_a2_firmware
|
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/sylogapply route. This could…
|
CWE-78
OS Command
|
CVE-2018-17064
|
2024-11-21 12:53 |
2018-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246946
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-816_a2_firmware
|
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/NTPSyncWithHost route. This …
|
CWE-78
OS Command
|
CVE-2018-17063
|
2024-11-21 12:53 |
2018-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246947
|
6.1 |
MEDIUM
Network
|
bullguard
|
safe_browsing
|
BullGuard Safe Browsing before 18.1.355.9 allows XSS on Google, Bing, and Yahoo! pages via domains indexed in search results.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17061
|
2024-11-21 12:53 |
2018-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246948
|
7.5 |
HIGH
Network
|
lg
|
supersign_cms
|
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2018-16706
|
2024-11-21 12:53 |
2018-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246949
|
9.8 |
CRITICAL
Network
|
tecnick limesurvey
|
tcpdf limesurvey
|
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-17057
|
2024-11-21 12:53 |
2018-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246950
|
6.1 |
MEDIUM
Network
|
knet
|
cisco_configuration_manager
|
K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17051
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|