|
247261
|
9.8 |
CRITICAL
Network
|
ca
|
identity_manager_virtual_appliance identity_manager
|
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.
|
CWE-200
Information Exposure
|
CVE-2017-9393
|
2024-11-21 12:36 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247262
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed wh…
|
CWE-682
Incorrect Calculation
|
CVE-2017-9725
|
2024-11-21 12:36 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247263
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, user-level permissions can be used to gain access to kernel memory, specifically the ION cache maintenance code is writ…
|
CWE-269
Improper Privilege Management
|
CVE-2017-9724
|
2024-11-21 12:36 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247264
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to an off-by-one error in a camera driver, an out-of-bounds read/write can occur.
|
CWE-193
Off-by-one Error
|
CVE-2017-9720
|
2024-11-21 12:36 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247265
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, variable "ddp->params_length" could be accessed and modified by multiple threads, w…
|
CWE-119 CWE-362
Incorrect Access of Indexable Resource ('Range Error') Race Condition
|
CVE-2017-9677
|
2024-11-21 12:36 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247266
|
4.7 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and race conditions can occur when accessing global static variables without using a…
|
CWE-200 CWE-362 CWE-416
Information Exposure Race Condition Use After Free
|
CVE-2017-9676
|
2024-11-21 12:36 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247267
|
7.5 |
HIGH
Network
|
apache
|
struts
|
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which …
|
CWE-20
Improper Input Validation
|
CVE-2017-9804
|
2024-11-21 12:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247268
|
7.5 |
HIGH
Network
|
apache
|
struts
|
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request wit…
|
CWE-20
Improper Input Validation
|
CVE-2017-9793
|
2024-11-21 12:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247269
|
5.0 |
MEDIUM
Adjacent
|
mirion_technologies
|
dmc_3000_firmware ipam_transmitter_f\/dmc_2000_firmware telepole_ii_firmware rds-31_itx_firmware rsd31-am_firmware wrm2_mesh_repeater_firmware drm-1\/2_firmware
|
A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-9649
|
2024-11-21 12:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247270
|
6.5 |
MEDIUM
Adjacent
|
mirion
|
dmc_3000_transmitter_firmware ipam_transmitter_f\/dmc_2000_firmware rds-31_itx_firmware drm-1\/2_firmware drm-2_firmware rds-31_firmware telepole_2_firmware wrm2_firmware
|
An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 a…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-9645
|
2024-11-21 12:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|