|
247881
|
8.8 |
HIGH
Network
|
mcafee
|
network_security_manager
|
Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers to perform unauthorized…
|
CWE-352
Origin Validation Error
|
CVE-2017-3965
|
2024-11-21 12:26 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247882
|
5.4 |
MEDIUM
Network
|
mcafee
|
network_security_manager
|
Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to inject arbitrary web script or HTML via a UR…
|
CWE-79
Cross-site Scripting
|
CVE-2017-3964
|
2024-11-21 12:26 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247883
|
4.4 |
MEDIUM
Local
|
mcafee
|
anti-virus_plus endpoint_security host_intrusion_prevention internet_security total_protection virus_scan_enterprise
|
Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee pr…
|
CWE-74
Injection
|
CVE-2017-4028
|
2024-11-21 12:26 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247884
|
9.8 |
CRITICAL
Network
|
mcafee
|
network_security_manager
|
Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to execute arbitrary code via the server banner le…
|
CWE-200
Information Exposure
|
CVE-2017-3972
|
2024-11-21 12:26 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247885
|
8.8 |
HIGH
Network
|
vmware
|
airwatch
|
VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking …
|
CWE-352
Origin Validation Error
|
CVE-2017-4951
|
2024-11-21 12:26 |
2018-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247886
|
9.8 |
CRITICAL
Network
|
vmware
|
vrealize_automation vsphere_integrated_containers
|
VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote a…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-4947
|
2024-11-21 12:26 |
2018-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247887
|
7.5 |
HIGH
Network
|
lenova ibm
|
flex_system_x240_m5_firmware flex_system_x280_x6_firmware flex_system_x440_m4_firmware flex_system_x480_x6_firmware flex_system_x880_firmware nextscale_nx360_m5_firmware system_x325…
|
An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earlier than 4.4 for Lenovo System x and earlier than 6.4 for IBM System x). Floodi…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-3768
|
2024-11-21 12:26 |
2018-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247888
|
7.8 |
HIGH
Local
|
lenovo
|
fingerprint_manager_pro
|
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-3762
|
2024-11-21 12:26 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247889
|
7.0 |
HIGH
Local
|
vmware
|
fusion workstation
|
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-4950
|
2024-11-21 12:26 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247890
|
7.0 |
HIGH
Local
|
vmware
|
fusion workstation
|
VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow a guest to execute code on the host. Note: IPv6 mode for VMN…
|
CWE-416
Use After Free
|
CVE-2017-4949
|
2024-11-21 12:26 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|