|
245571
|
9.8 |
CRITICAL
Network
|
sharing-file
|
easy_file_sharing_web_server
|
An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious POST request has been made to forum.ghp upon creating a new topi…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-18912
|
2024-11-21 12:56 |
2019-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245572
|
5.4 |
MEDIUM
Network
|
kieranoshea
|
calendar
|
The Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a wp-admin/admin.php?page=calendar add action, or the category name during category creat…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18872
|
2024-11-21 12:56 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245573
|
6.1 |
MEDIUM
Network
|
evernote
|
evernote
|
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note unde…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18524
|
2024-11-21 12:56 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245574
|
6.4 |
MEDIUM
Physics
|
espressif
|
esp-idf
|
An issue was discovered in Espressif ESP-IDF 2.x and 3.x before 3.0.6 and 3.1.x before 3.1.1. Insufficient validation of input data in the 2nd stage bootloader allows a physically proximate attacker …
|
CWE-20
Improper Input Validation
|
CVE-2018-18558
|
2024-11-21 12:56 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245575
|
7.4 |
HIGH
Network
|
ascensia
|
contour_diabetes
|
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption key. Extraction of the encryption key is necessary for deciphe…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-18978
|
2024-11-21 12:56 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245576
|
7.5 |
HIGH
Network
|
ascensia
|
contour_diabetes
|
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reverse engineer the codebase to extract sensitive data that contributes to the dis…
|
CWE-200
Information Exposure
|
CVE-2018-18977
|
2024-11-21 12:56 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245577
|
5.3 |
MEDIUM
Network
|
ascensia
|
contour_diabetes
|
An issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve encrypted medical information of any user of the Ascensia cloud pl…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-18976
|
2024-11-21 12:56 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245578
|
7.5 |
HIGH
Network
|
ascensia
|
contour_diabetes
|
An issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communications between the app and Ascensia backend servers because of a weak certificate…
|
CWE-200
Information Exposure
|
CVE-2018-18975
|
2024-11-21 12:56 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245579
|
7.4 |
HIGH
Network
|
ascensia
|
contour_diabetes
|
An issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded initialization vector. Extraction of the initialization vector is necessa…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-18979
|
2024-11-21 12:56 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245580
|
7.5 |
HIGH
Network
|
mozilla
|
thunderbird
|
A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-18513
|
2024-11-21 12:56 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|