|
249271
|
6.1 |
MEDIUM
Network
|
archon_project
|
archon
|
packages/subjects/pub/subjects.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?subjecttypeid=xxx request, aka Open Bug Bounty ID OBB-466362.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17972
|
2024-11-21 12:19 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249272
|
9.1 |
CRITICAL
Network
|
asus
|
vivobaby hivivo
|
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-17945
|
2024-11-21 12:19 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249273
|
9.1 |
CRITICAL
Network
|
asus
|
vivobaby hivivo
|
The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-17944
|
2024-11-21 12:19 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249274
|
9.8 |
CRITICAL
Network
|
netgear
|
readynas_surveillance_firmware
|
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=wri…
|
CWE-77
Command Injection
|
CVE-2017-18378
|
2024-11-21 12:19 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249275
|
9.8 |
CRITICAL
Network
|
goahead
|
wireless_ip_camera_wificam_firmware
|
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cg…
|
CWE-77
Command Injection
|
CVE-2017-18377
|
2024-11-21 12:19 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249276
|
8.8 |
HIGH
Network
|
strangebee
|
thehive
|
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's priv…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18376
|
2024-11-21 12:19 |
2019-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249277
|
8.8 |
HIGH
Network
|
ampache
|
ampache
|
Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-18375
|
2024-11-21 12:19 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249278
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware sd_210_firmware sd_835_firmware sd_845_firmware sd_850_firmware sd_212_firmware sd_205_firmware
|
Secure camera logic allows display/secure camera controllers to access HLOS memory during secure display or camera session in Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, SD 210/S…
|
NVD-CWE-noinfo
|
CVE-2017-18276
|
2024-11-21 12:19 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249279
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd…
|
While processing camera buffers in camera driver, a use after free condition can occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD …
|
CWE-416
Use After Free
|
CVE-2017-18156
|
2024-11-21 12:19 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249280
|
7.8 |
HIGH
Local
|
qualcomm
|
fsm9055_firmware fsm9955_firmware ipq4019_firmware mdm9206_firmware mdm9607_firmware mdm9640_firmware mdm9650_firmware msm8909w_firmware msm8996au_firmware qca9531_firmware…
|
Lack of check of buffer length before copying can lead to buffer overflow in camera module in Small Cell SoC, Snapdragon Mobile, Snapdragon Wear in FSM9055, FSM9955, IPQ4019, IPQ8064, MDM9206, MDM960…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-18279
|
2024-11-21 12:19 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|