|
245611
|
6.1 |
MEDIUM
Network
|
semcosoft
|
semcosoft
|
A reflected Cross-Site scripting (XSS) vulnerability in SEMCO Semcosoft 5.3 allows remote attackers to inject arbitrary web scripts or HTML via the username parameter to the Login Form.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18692
|
2024-11-21 12:56 |
2019-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245612
|
8.6 |
HIGH
Network
|
dundas
|
dundas_bi
|
The Dundas BI server before 5.0.1.1010 is vulnerable to a Server-Side Request Forgery attack, allowing an attacker to forge arbitrary requests (with certain restrictions) that will be executed on beh…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-18569
|
2024-11-21 12:56 |
2019-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245613
|
5.9 |
MEDIUM
Network
|
mozilla canonical debian redhat opensuse
|
firefox ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus enterpr…
|
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to …
|
NVD-CWE-noinfo
|
CVE-2018-18506
|
2024-11-21 12:56 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245614
|
10.0 |
CRITICAL
Network
|
mozilla canonical debian redhat
|
firefox thunderbird firefox_esr ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterpri…
|
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This …
|
CWE-287
Improper Authentication
|
CVE-2018-18505
|
2024-11-21 12:56 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245615
|
9.8 |
CRITICAL
Network
|
mozilla canonical
|
firefox ubuntu_linux
|
A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This results is a potentially exploitable crash and the possi…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-18504
|
2024-11-21 12:56 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245616
|
8.8 |
HIGH
Network
|
mozilla canonical
|
firefox ubuntu_linux
|
When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some situations. This vulnerability affects Firefox < …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18503
|
2024-11-21 12:56 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245617
|
9.8 |
CRITICAL
Network
|
mozilla canonical
|
firefox ubuntu_linux
|
Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18502
|
2024-11-21 12:56 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245618
|
9.8 |
CRITICAL
Network
|
mozilla canonical debian redhat
|
firefox thunderbird firefox_esr ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterpri…
|
Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18501
|
2024-11-21 12:56 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245619
|
9.8 |
CRITICAL
Network
|
mozilla canonical debian redhat
|
firefox thunderbird firefox_esr ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterpri…
|
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a pote…
|
CWE-416
Use After Free
|
CVE-2018-18500
|
2024-11-21 12:56 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245620
|
5.3 |
MEDIUM
Network
|
lcds
|
laquis_scada
|
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information …
|
CWE-22
Path Traversal
|
CVE-2018-18990
|
2024-11-21 12:56 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|