|
248441
|
7.5 |
HIGH
Network
|
rockwellautomation
|
rslinx
|
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally send specially crafted Ethernet/IP packets to Port 44818, causing the software …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-14827
|
2024-11-21 12:49 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248442
|
7.5 |
HIGH
Network
|
rockwellautomation
|
rslinx
|
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote, unauthenticated threat actor to intentionally send a malformed CIP packet to Port 44818, causing …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14821
|
2024-11-21 12:49 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248443
|
7.5 |
HIGH
Network
|
tec4data
|
smartcooler_firmware
|
Tec4Data SmartCooler, all versions prior to firmware 180806, the device responds to a remote unauthenticated reboot command that may be used to perform a denial of service attack.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-14796
|
2024-11-21 12:49 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248444
|
6.3 |
MEDIUM
Network
|
we-con
|
plc_editor
|
WECON PLC Editor version 1.3.3U may allow an attacker to execute code under the current process when processing project files.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14792
|
2024-11-21 12:49 |
2018-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248445
|
5.3 |
MEDIUM
Network
|
redhat
|
undertow jboss_enterprise_application_platform
|
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full con…
|
CWE-200
Information Exposure
|
CVE-2018-14642
|
2024-11-21 12:49 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248446
|
5.9 |
MEDIUM
Network
|
linux
|
linux_kernel
|
A security flaw was found in the ip_frag_reasm() function in net/ipv4/ip_fragment.c in the Linux kernel from 4.19-rc1 to 4.19-rc3 inclusive, which can cause a later system crash in ip_do_fragment(). …
|
CWE-20
Improper Input Validation
|
CVE-2018-14641
|
2024-11-21 12:49 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248447
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
moodle before versions 3.5.2, 3.4.5, 3.3.8 is vulnerable to a boost theme - blog search GET parameter insufficiently filtered. The breadcrumb navigation provided by Boost theme when displaying search…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14631
|
2024-11-21 12:49 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248448
|
8.8 |
HIGH
Network
|
moodle
|
moodle
|
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) t…
|
CWE-94
Code Injection
|
CVE-2018-14630
|
2024-11-21 12:49 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248449
|
7.5 |
HIGH
Network
|
fedoraproject redhat
|
389_directory_server enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_aus
|
A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remot…
|
CWE-415
Double Free
|
CVE-2018-14638
|
2024-11-21 12:49 |
2018-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248450
|
5.3 |
MEDIUM
Network
|
openstack
|
neutron
|
Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended indefinitely if the instance's port is set administratively…
|
NVD-CWE-noinfo
|
CVE-2018-14636
|
2024-11-21 12:49 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|