|
247731
|
3.9 |
LOW
Physics
|
intel
|
nuc6i3syh_bios nuc6i3syk_bios
|
The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version SY0059 may allow may allow an attacker with physical access to the system to gain access to personal information.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-5686
|
2024-11-21 12:28 |
2017-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247732
|
3.9 |
LOW
Physics
|
intel
|
nuc6i7kyk_bios
|
The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version KY0045 may allow may allow an attacker with physical access to the system to gain access to personal information.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-5685
|
2024-11-21 12:28 |
2017-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247733
|
3.9 |
LOW
Physics
|
intel
|
stk2mv64cc_bios
|
The BIOS in Intel Compute Stick systems based on 6th Gen Intel Core processors prior to version CC047 may allow an attacker with physical access to the system to gain access to personal information.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-5684
|
2024-11-21 12:28 |
2017-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247734
|
9.8 |
CRITICAL
Network
|
apache
|
ambari
|
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-5642
|
2024-11-21 12:28 |
2017-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247735
|
5.5 |
MEDIUM
Local
|
artifex
|
ghostscript
|
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-5951
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247736
|
5.5 |
MEDIUM
Local
|
yaml-cpp_project
|
yaml-cpp
|
The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5950
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247737
|
9.8 |
CRITICAL
Network
|
apple
|
safari
|
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possib…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-5949
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247738
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_compiler_destroy function.
|
CWE-416
Use After Free
|
CVE-2017-5924
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247739
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted rule that is mishandled in the yara_yyparse fu…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5923
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247740
|
5.4 |
MEDIUM
Network
|
netcomm
|
nb16wv-02_firmware
|
Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02 router with firmware NB16WV_R0.09 allows remote authenticated users to inject arbitrary web script or HTML via the S801F0334 paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5900
|
2024-11-21 12:28 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|