|
249001
|
4.6 |
MEDIUM
Physics
|
st
|
stm32f071rb_firmware stm32f071v8_firmware stm32f071vb_firmware stm32f072c8_firmware stm32f072cb_firmware stm32f072r8_firmware stm32f072rb_firmware stm32f072v8_firmware stm32f0…
|
Incorrect access control in RDP Level 1 on STMicroelectronics STM32F0 series devices allows physically present attackers to extract the device's protected firmware via a special sequence of Serial Wi…
|
CWE-362
Race Condition
|
CVE-2017-18347
|
2024-11-21 12:19 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249002
|
9.8 |
CRITICAL
Network
|
joomanager_project
|
joomanager
|
The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=detail…
|
CWE-200
Information Exposure
|
CVE-2017-18345
|
2024-11-21 12:19 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249003
|
5.5 |
MEDIUM
Local
|
linux canonical redhat
|
linux_kernel ubuntu_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterprise_linux_s…
|
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-18344
|
2024-11-21 12:19 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249004
|
5.9 |
MEDIUM
Network
|
atlassian
|
jira jira_server
|
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to lea…
|
CWE-200
Information Exposure
|
CVE-2017-18104
|
2024-11-21 12:19 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249005
|
6.1 |
MEDIUM
Network
|
sensiolabs
|
symfony
|
The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as de…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18343
|
2024-11-21 12:19 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249006
|
4.7 |
MEDIUM
Network
|
atlassian
|
http_library
|
The atlassian-http library, as used in various Atlassian products, before version 2.0.2 allows remote attackers to spoof web content in the Mozilla Firefox Browser through uploaded files that have a …
|
CWE-20
Improper Input Validation
|
CVE-2017-18103
|
2024-11-21 12:19 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249007
|
7.8 |
HIGH
Local
|
qualcomm
|
msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware
|
While playing HEVC content using HD DMB in Snapdragon Automobile and Snapdragon Mobile in version MSM8996AU, SD 450, SD 625, SD 820, SD 820A, SD 835, an uninitialized variable can be used leading to …
|
CWE-20
Improper Input Validation
|
CVE-2017-18155
|
2024-11-21 12:19 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249008
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, while processing a StrHwPlatform with length smaller tha…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-18159
|
2024-11-21 12:19 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249009
|
7.8 |
HIGH
Local
|
google
|
android
|
Possible buffer overflows and array out of bounds accesses in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-0…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-18158
|
2024-11-21 12:19 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249010
|
9.8 |
CRITICAL
Network
|
pyyaml fedoraproject
|
pyyaml fedora
|
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced f…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-18342
|
2024-11-21 12:19 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|