|
251771
|
9.8 |
CRITICAL
Network
|
orpak
|
siteomat
|
An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to captur…
|
CWE-310
Cryptographic Issues
|
CVE-2017-14852
|
2024-11-21 12:13 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251772
|
9.8 |
CRITICAL
Network
|
orpak
|
siteomat
|
A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELEC…
|
CWE-89
SQL Injection
|
CVE-2017-14851
|
2024-11-21 12:13 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251773
|
6.1 |
MEDIUM
Network
|
orpak
|
siteomat
|
All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. An attacker with acc…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14850
|
2024-11-21 12:13 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251774
|
9.8 |
CRITICAL
Network
|
orpak
|
siteomat
|
An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affected, prior to the submission of this exploit. Also, the SiteOmat does not force a…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-14728
|
2024-11-21 12:13 |
2019-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251775
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2017-15030
|
2024-11-21 12:13 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251776
|
4.3 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-15029
|
2024-11-21 12:13 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251777
|
7.5 |
HIGH
Network
|
arm
|
arm-trusted-firmware
|
In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.
|
CWE-200
Information Exposure
|
CVE-2017-15031
|
2024-11-21 12:13 |
2018-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251778
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Userspace can pass IEs to the host driver and if multiple append commands are received, then…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14888
|
2024-11-21 12:13 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251779
|
5.9 |
MEDIUM
Network
|
shein
|
shein-fashion_shopping_online
|
The Shein Group Ltd. "SHEIN - Fashion Shopping" app -- aka shein fashion-shopping/id878577184 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers …
|
CWE-295
Improper Certificate Validation
|
CVE-2017-14710
|
2024-11-21 12:13 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251780
|
7.4 |
HIGH
Network
|
komoot
|
komoot
|
The komoot GmbH "Komoot - Cycling & Hiking Maps" app before 9.3.2 -- aka komoot-cycling-hiking-maps/id447374873 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the…
|
CWE-200 CWE-295
Information Exposure Improper Certificate Validation
|
CVE-2017-14709
|
2024-11-21 12:13 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|