Latest CVE Feed
-
7.8
HIGHCVE-2018-10953
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x0022204C.... Read more
Affected Products : 2345_security_guard- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10952
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222088.... Read more
Affected Products : 2345_security_guard- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-10950
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 before 8.6.0.Patch10 allows Information Exposure through Verbose Error Messages containing a stack dump, tracing data, or full user-context dump.... Read more
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-10949
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.... Read more
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-10948
Synacor Zimbra Admin UI in Zimbra Collaboration Suite before 8.8.0 beta 2 has Persistent XSS via mail addrs.... Read more
Affected Products : zimbra_collaboration_suite- Published: May. 30, 2019
- Modified: Nov. 21, 2024
-
3.1
LOWCVE-2018-10947
An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset only after a Debut is rebooted.... Read more
- Published: Jun. 13, 2019
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2018-10946
An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the admin user's password via the admin web UI.... Read more
- Published: Jun. 13, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10945
The mg_handle_cgi function in mongoose.c in Mongoose 6.11 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash, or NULL pointer dereference) via an HTTP request, related to the mbuf_insert function.... Read more
Affected Products : mongoose- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-10944
The request_dividend function of a smart contract implementation for ROC (aka Rasputin Online Coin), an Ethereum ERC20 token, allows attackers to steal all of the contract's Ether.... Read more
Affected Products : rasputin_online_coin- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10943
An issue was discovered on Barco ClickShare CSE-200 and CS-100 Base Units with firmware before 1.6.0.3. Sending an arbitrary unexpected string to TCP port 7100 respecting a certain frequency timing disconnects all clients and results in a crash of the Uni... Read more
Affected Products : clickshare_cse-200_firmware clickshare_cs-100_firmware clickshare_cse-200 clickshare_cs-100- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10942
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.... Read more
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10940
The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers to use a incorrect bounds check in the CDROM driver CDROM_MEDIA_CHANGED ioctl to read out kernel memory.... Read more
- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10939
Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2018-10938
A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a... Read more
- Published: Aug. 27, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10937
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.... Read more
Affected Products : openshift_container_platform- Published: Sep. 11, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-10936
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker ... Read more
- Published: Aug. 30, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10935
A flaw was found in the 389 Directory Server that allows users to cause a crash in the LDAP server using ldapsearch with server side sort.... Read more
- Published: Sep. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10934
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.... Read more
- Published: Mar. 27, 2019
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2018-10933
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.... Read more
- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-10932
lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.... Read more
Affected Products : lldptool- Published: Aug. 21, 2018
- Modified: Nov. 21, 2024