|
247291
|
7.8 |
HIGH
Local
|
omron
|
cx-protocol cx-one
|
Three type confusion vulnerabilities exist in CX-One Versions 4.50 and prior and CX-Protocol Versions 2.0 and prior when processing project files. An attacker could use a specially crafted project fi…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-19027
|
2024-11-21 12:57 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247292
|
5.3 |
MEDIUM
Network
|
arm
|
trusted_firmware-a
|
ARM Trusted Firmware-A allows information disclosure.
|
CWE-200
Information Exposure
|
CVE-2018-19440
|
2024-11-21 12:57 |
2019-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247293
|
6.5 |
MEDIUM
Adjacent
|
draeger
|
kappa_firmware infinity_explorer_c700_firmware delta_xl_firmware infinity_delta_firmware
|
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network con…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-19014
|
2024-11-21 12:57 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247294
|
6.5 |
MEDIUM
Adjacent
|
draeger
|
kappa_firmware infinity_explorer_c700_firmware delta_xl_firmware infinity_delta_firmware
|
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malformed network packet may cause the monitor to reboot. …
|
CWE-20
Improper Input Validation
|
CVE-2018-19010
|
2024-11-21 12:57 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247295
|
7.8 |
HIGH
Local
|
draeger
|
kappa_firmware infinity_explorer_c700_firmware delta_xl_firmware infinity_delta_firmware
|
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kio…
|
NVD-CWE-noinfo
|
CVE-2018-19012
|
2024-11-21 12:57 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247296
|
7.3 |
HIGH
Local
|
omron
|
cx-supervisor
|
An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attacker could exploit t…
|
CWE-78
OS Command
|
CVE-2018-19015
|
2024-11-21 12:57 |
2019-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247297
|
8.8 |
HIGH
Adjacent
|
hetronic
|
nova-m_firmware es-can-hl_firmware bms-hl_firmware mlc_firmware dc_mobile_firmware
|
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or ke…
|
CWE-287
Improper Authentication
|
CVE-2018-19023
|
2024-11-21 12:57 |
2019-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247298
|
6.5 |
MEDIUM
Adjacent
|
emerson
|
deltav
|
A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3.1, 14.3, R5.1, R6 and prior, which may allow an attacker t…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2018-19021
|
2024-11-21 12:57 |
2019-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247299
|
7.8 |
HIGH
Local
|
pilz
|
pnozmulti_configurator
|
Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti Configurator software to view sensitive credential data in …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2018-19009
|
2024-11-21 12:57 |
2019-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247300
|
7.3 |
HIGH
Local
|
omron
|
cx-supervisor
|
A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code unde…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-19019
|
2024-11-21 12:57 |
2019-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|