|
256131
|
8.1 |
HIGH
Network
|
rubygems debian canonical redhat
|
rubygems debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterp…
|
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacke…
|
CWE-346
Origin Validation Error
|
CVE-2017-0902
|
2024-11-21 12:03 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256132
|
7.5 |
HIGH
Network
|
rubygems debian canonical redhat
|
rubygems debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterp…
|
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
|
CWE-20
Improper Input Validation
|
CVE-2017-0901
|
2024-11-21 12:03 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256133
|
7.5 |
HIGH
Network
|
rubygems debian redhat
|
rubygems debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_serve…
|
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.
|
CWE-20
Improper Input Validation
|
CVE-2017-0900
|
2024-11-21 12:03 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256134
|
9.8 |
CRITICAL
Network
|
rubygems debian redhat
|
rubygems debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_serve…
|
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape seque…
|
CWE-94
Code Injection
|
CVE-2017-0899
|
2024-11-21 12:03 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256135
|
7.8 |
HIGH
Local
|
google
|
android
|
A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237701.
|
CWE-129
Improper Validation of Array Index
|
CVE-2017-0805
|
2024-11-21 12:03 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256136
|
5.5 |
MEDIUM
Local
|
google
|
android
|
A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35583675.
|
NVD-CWE-noinfo
|
CVE-2017-0687
|
2024-11-21 12:03 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256137
|
7.8 |
HIGH
Local
|
google
|
android
|
A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions: Android kernel. Android ID: A-36817013.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-0750
|
2024-11-21 12:03 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256138
|
7.8 |
HIGH
Local
|
google
|
android
|
A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Versions: Android kernel. Android ID: A-36007735.
|
NVD-CWE-noinfo
|
CVE-2017-0749
|
2024-11-21 12:03 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256139
|
7.8 |
HIGH
Local
|
google
|
android
|
A elevation of privilege vulnerability in the Qualcomm proprietary component. Product: Android. Versions: Android kernel. Android ID: A-32524214. References: QC-CR#2044821.
|
NVD-CWE-noinfo
|
CVE-2017-0747
|
2024-11-21 12:03 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256140
|
7.8 |
HIGH
Local
|
google
|
android
|
A elevation of privilege vulnerability in the Qualcomm ipa driver. Product: Android. Versions: Android kernel. Android ID: A-35467471. References: QC-CR#2029392.
|
NVD-CWE-noinfo
|
CVE-2017-0746
|
2024-11-21 12:03 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|