Show filters
275 Total Results
Displaying 171-180 of 275
Sort by:
Attacker Value
Unknown
CVE-2018-13741
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for ABLGenesisToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2018-11525
Disclosure Date: June 19, 2018 (last updated November 21, 2024)
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
0
Attacker Value
Unknown
CVE-2018-10229
Disclosure Date: May 04, 2018 (last updated November 26, 2024)
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.
0
Attacker Value
Unknown
CVE-2018-10285
Disclosure Date: April 22, 2018 (last updated November 26, 2024)
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.
0
Attacker Value
Unknown
CVE-2018-10286
Disclosure Date: April 22, 2018 (last updated November 26, 2024)
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the credentials in cleartext, an attacker needs to be authenticated.
0
Attacker Value
Unknown
CVE-2018-9245
Disclosure Date: April 22, 2018 (last updated November 26, 2024)
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.
0
Attacker Value
Unknown
CVE-2018-10173
Disclosure Date: April 20, 2018 (last updated November 26, 2024)
Digital Guardian Management Console 7.1.2.0015 allows authenticated remote code execution because of Arbitrary File Upload functionality.
0
Attacker Value
Unknown
CVE-2018-10176
Disclosure Date: April 20, 2018 (last updated November 26, 2024)
Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue.
0
Attacker Value
Unknown
CVE-2018-10174
Disclosure Date: April 20, 2018 (last updated November 26, 2024)
Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user has a read-only role.
0
Attacker Value
Unknown
CVE-2018-10175
Disclosure Date: April 20, 2018 (last updated November 26, 2024)
Digital Guardian Management Console 7.1.2.0015 has an XXE issue.
0