Latest CVE Feed
-
7.4
HIGHCVE-2018-0650
The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : line_music- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0649
Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except pa... Read more
Affected Products : nod32_antivirus smart_security compusec deslock\+_pro internet_security smart_security_premium- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0648
Untrusted search path vulnerability in installer of ChatWork Desktop App for Windows 2.3.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : chatwork- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0647
Cross-site request forgery (CSRF) vulnerability in WL-330NUL Firmware version prior to 3.0.0.46 allows remote attackers to hijack the authentication of administrators via unspecified vectors.... Read more
- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0646
Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecified vectors.... Read more
Affected Products : explzh- Published: Sep. 04, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-0645
MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors.... Read more
Affected Products : mtappjquery- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-0644
Buffer overflow in Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-client2) 1:1.4.9+p41-u4jma1 and earlier, Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 5.0.0 (panda-client2) 1:2.0.0+p48-u4jma1 and earlier, and Ubuntu16.04 ORCA (... Read more
Affected Products : ubuntu_linux- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2018-0643
Ubuntu14.04 ORCA (Online Receipt Computer Advantage) 4.8.0 (panda-server) 1:1.4.9+p41-u4jma1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0642
Cross-site scripting vulnerability in FV Flowplayer Video Player 6.1.2 to 6.6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : fv_flowplayer_video_player- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0641
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via tools_system.cgi date parameter, time parameter, and offset parameter.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0640
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-0639
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, time parameter, and offset parameter.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-0638
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-0637
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via export.cgi encKey parameter.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-0636
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a certain URL, different URL from CVE-2018-0634.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-0635
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via filename parameter.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-0634
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter or bootmode parameter of a certain URL.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0633
Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via submit-url parameter.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-0632
Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via HTTP request and response.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-0631
Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.... Read more
- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024