|
247191
|
6.1 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8808
|
2024-11-21 12:34 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247192
|
7.5 |
HIGH
Network
|
microsoft
|
asp.net_core
|
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Infor…
|
NVD-CWE-noinfo
|
CVE-2017-8700
|
2024-11-21 12:34 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247193
|
5.5 |
MEDIUM
Local
|
postgresql
|
postgresql
|
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debia…
|
CWE-59
Link Following
|
CVE-2017-8806
|
2024-11-21 12:34 |
2017-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247194
|
9.1 |
CRITICAL
Network
|
debian
|
ftpsync
|
Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.
|
CWE-22
Path Traversal
|
CVE-2017-8805
|
2024-11-21 12:34 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247195
|
4.3 |
MEDIUM
Network
|
microsoft
|
edge
|
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how affected Microsoft s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8726
|
2024-11-21 12:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247196
|
5.3 |
MEDIUM
Local
|
microsoft
|
windows_server_2016 windows_10
|
The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass by the way it handles Windows PowerShell sessions, aka "Windows…
|
NVD-CWE-noinfo
|
CVE-2017-8715
|
2024-11-21 12:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247197
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10
|
The Microsoft Windows Subsystem for Linux on Microsoft Windows 10 1703 allows a denial of service vulnerability when it improperly handles objects in memory, aka "Windows Subsystem for Linux Denial o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8703
|
2024-11-21 12:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247198
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2016 windows_10
|
The Microsoft Graphics Component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability in the way it handles objects in memory, ak…
|
CWE-200
Information Exposure
|
CVE-2017-8693
|
2024-11-21 12:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247199
|
7.5 |
HIGH
Network
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008
|
Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execut…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8727
|
2024-11-21 12:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247200
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008
|
The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8718
|
2024-11-21 12:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|