|
248411
|
6.5 |
MEDIUM
Network
|
apple
|
safari iphone_os tvos
|
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remo…
|
NVD-CWE-noinfo
|
CVE-2017-2367
|
2024-11-21 12:23 |
2017-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248412
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value fo…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-2647
|
2024-11-21 12:23 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248413
|
8.8 |
HIGH
Network
|
siemens
|
ruggedcom_rox_i
|
Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or change configuration…
|
CWE-287
Improper Authentication
|
CVE-2017-2689
|
2024-11-21 12:23 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248414
|
8.8 |
HIGH
Network
|
siemens
|
ruggedcom_rox_i
|
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the target…
|
CWE-352
Origin Validation Error
|
CVE-2017-2688
|
2024-11-21 12:23 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248415
|
6.1 |
MEDIUM
Network
|
siemens
|
ruggedcom_rox_i
|
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site Scripting attacks if an unsuspecting user is induc…
|
CWE-79
Cross-site Scripting
|
CVE-2017-2687
|
2024-11-21 12:23 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248416
|
6.5 |
MEDIUM
Network
|
siemens
|
ruggedcom_rox_i
|
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and access sensitive informat…
|
CWE-200
Information Exposure
|
CVE-2017-2686
|
2024-11-21 12:23 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248417
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
|
CWE-79
Cross-site Scripting
|
CVE-2017-2645
|
2024-11-21 12:23 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248418
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.x, XSS can occur via evidence of prior learning.
|
CWE-79
Cross-site Scripting
|
CVE-2017-2644
|
2024-11-21 12:23 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248419
|
5.3 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.2.x, global search displays user names for unauthenticated users.
|
CWE-200
Information Exposure
|
CVE-2017-2643
|
2024-11-21 12:23 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248420
|
9.8 |
CRITICAL
Network
|
moodle
|
moodle
|
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
|
CWE-89
SQL Injection
|
CVE-2017-2641
|
2024-11-21 12:23 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|