|
255081
|
7.5 |
HIGH
Network
|
redhat debian novell canonical fedoraproject thekelleys
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux leap ubuntu_linux fedora dnsmasq
|
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0x…
|
CWE-20
Improper Input Validation
|
CVE-2017-13704
|
2024-11-21 12:11 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255082
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
wonderware_intouch wonderware_indusoft_web_studio
|
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio pro…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-13997
|
2024-11-21 12:11 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255083
|
5.3 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.
|
CWE-200
Information Exposure
|
CVE-2017-13991
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255084
|
5.3 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.
|
CWE-200
Information Exposure
|
CVE-2017-13990
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255085
|
8.1 |
HIGH
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage i…
|
NVD-CWE-noinfo
|
CVE-2017-13989
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255086
|
6.5 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of st…
|
NVD-CWE-noinfo
|
CVE-2017-13988
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255087
|
6.5 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files.
|
NVD-CWE-noinfo
|
CVE-2017-13987
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255088
|
6.1 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a speci…
|
CWE-79
Cross-site Scripting
|
CVE-2017-13986
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255089
|
6.5 |
MEDIUM
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclos…
|
CWE-22
Path Traversal
|
CVE-2017-13985
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255090
|
6.5 |
MEDIUM
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet di…
|
CWE-287
Improper Authentication
|
CVE-2017-13984
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|