|
246581
|
7.5 |
HIGH
Network
|
ptc
|
thingworx_platform
|
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-17217
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246582
|
6.5 |
MEDIUM
Network
|
ptc
|
thingworx_platform
|
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users.
|
CWE-200
Information Exposure
|
CVE-2018-17216
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246583
|
6.5 |
MEDIUM
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can…
|
CWE-22
Path Traversal
|
CVE-2018-17797
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246584
|
9.8 |
CRITICAL
Network
|
mushroom_content_management_system_project
|
mushroom_content_management_system
|
An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T parameter in a request and uses it as a hash of SQL statements without filtering, re…
|
CWE-89
SQL Injection
|
CVE-2018-17796
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246585
|
8.8 |
HIGH
Network
|
libtiff
|
libtiff
|
The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecif…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17795
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246586
|
6.5 |
MEDIUM
Network
|
gnu
|
binutils
|
An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17794
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246587
|
7.5 |
HIGH
Network
|
blynk
|
blynk-server
|
In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file.
|
CWE-22
Path Traversal
|
CVE-2018-17785
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246588
|
6.5 |
MEDIUM
Network
|
telegram
|
telegram_desktop telegram_messenger
|
Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call because of an unsafe default behavior in which P2P connecti…
|
CWE-200
Information Exposure
|
CVE-2018-17780
|
2024-11-21 12:54 |
2018-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246589
|
7.5 |
HIGH
Network
|
foxitsoftware
|
phantompdf reader
|
Foxit PhantomPDF and Reader before 9.3 allow remote attackers to trigger Uninitialized Object Information Disclosure because creation of ArrayBuffer and DataView objects is mishandled.
|
CWE-200
Information Exposure
|
CVE-2018-17781
|
2024-11-21 12:54 |
2018-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246590
|
7.8 |
HIGH
Local
|
pcprotect
|
antivirus
|
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges by replacing an executable file with a Trojan horse.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-17776
|
2024-11-21 12:54 |
2018-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|