|
247021
|
9.8 |
CRITICAL
Network
|
rubedo_project
|
rubedo
|
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as d…
|
CWE-22
Path Traversal
|
CVE-2018-16836
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247022
|
6.5 |
MEDIUM
Network
|
xunfeng_project
|
xunfeng
|
CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of…
|
CWE-352
Origin Validation Error
|
CVE-2018-16832
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247023
|
5.9 |
MEDIUM
Network
|
smarty
|
smarty
|
Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in an include statement.
|
CWE-22
Path Traversal
|
CVE-2018-16831
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247024
|
7.5 |
HIGH
Network
|
bro
|
bro
|
In Bro through 2.5.5, there is a memory leak potentially leading to DoS in scripts/base/protocols/krb/main.bro in the Kerberos protocol parser.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-16807
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247025
|
6.5 |
MEDIUM
Adjacent
|
pektron
|
passive_keyless_entry_and_start_system_firmware
|
A Pektron Passive Keyless Entry and Start (PKES) system, as used on the Tesla Model S and possibly other vehicles, relies on the DST40 cipher, which makes it easier for attackers to obtain access via…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-16806
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247026
|
4.8 |
MEDIUM
Network
|
b3log
|
solo
|
In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16805
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247027
|
9.8 |
CRITICAL
Network
|
furuno
|
felcom_250_firmware felcom_500_firmware
|
FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords. This includes the Admin and Service user accounts…
|
CWE-200
Information Exposure
|
CVE-2018-16705
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247028
|
9.8 |
CRITICAL
Network
|
furuno
|
felcom_250_firmware felcom_500_firmware
|
FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_cha…
|
CWE-862
Missing Authorization
|
CVE-2018-16591
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247029
|
7.8 |
HIGH
Local
|
artifex debian canonical redhat
|
ghostscript debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus ent…
|
An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply…
|
NVD-CWE-noinfo
|
CVE-2018-16802
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247030
|
7.8 |
HIGH
Local
|
kakaocorp
|
potplayer
|
A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary code via a .wav file with large BytesPerSec and SamplesPerSec values, and a small …
|
CWE-787
Out-of-bounds Write
|
CVE-2018-16797
|
2024-11-21 12:53 |
2018-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|