|
250321
|
5.5 |
MEDIUM
Local
|
foxitsoftware
|
mobilepdf
|
A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs by abusing the URL + escape character during a Wi-Fi transfer, which could be exploited by attack…
|
CWE-22
Path Traversal
|
CVE-2017-16814
|
2024-11-21 12:17 |
2018-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250322
|
5.5 |
MEDIUM
Local
|
foxitsoftware
|
mobilepdf
|
A denial-of-service issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs when a user uploads a file that includes a hexadecimal Unicode character in the "filename" paramete…
|
CWE-20
Improper Input Validation
|
CVE-2017-16813
|
2024-11-21 12:17 |
2018-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250323
|
5.9 |
MEDIUM
Network
|
mahara
|
mahara
|
Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HT…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-17455
|
2024-11-21 12:17 |
2018-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250324
|
5.4 |
MEDIUM
Network
|
mahara
|
mahara
|
Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be di…
|
CWE-79
Cross-site Scripting
|
CVE-2017-17454
|
2024-11-21 12:17 |
2018-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250325
|
7.5 |
HIGH
Network
|
photo\ video_locker-calculator_project
|
photo\ video_locker-calculator
|
The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb ba…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2017-16835
|
2024-11-21 12:17 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250326
|
9.8 |
CRITICAL
Network
|
apexis
|
apm-h803-mpc_firmware
|
An issue was discovered in Apexis APM-H803-MPC software, as used with many different models of IP Camera. An unprotected CGI method inside the web application permits an unauthenticated user to bypas…
|
NVD-CWE-noinfo
|
CVE-2017-17101
|
2024-11-21 12:17 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250327
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central
|
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration polici…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2017-16924
|
2024-11-21 12:17 |
2018-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250328
|
8.8 |
HIGH
Adjacent
|
huawei
|
lon-al00b_firmware
|
Bluetooth module in some Huawei mobile phones with software LON-AL00BC00B229 and earlier versions has a buffer overflow vulnerability. Due to insufficient input validation, an unauthenticated attacke…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17285
|
2024-11-21 12:17 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250329
|
5.3 |
MEDIUM
Network
|
huawei
|
secospace_antiddos8000_firmware
|
Huawei Secospace AntiDDoS8000 V500R001C20SPC500 have a memory leak vulnerability due to memory don't be released when the system open some function. An attacker could exploit it to cause memory leak,…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-17164
|
2024-11-21 12:17 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250330
|
3.3 |
LOW
Local
|
huawei
|
dp300_firmware rp200_firmware te30_firmware te40_firmware te50_firmware te60_firmware
|
Huawei DP300 V500R002C00, RP200 V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-17302
|
2024-11-21 12:17 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|