|
251691
|
8.8 |
HIGH
Network
|
huawei
|
smartcare
|
Huawei SmartCare V200R003C10 has a CSV injection vulnerability. An remote authenticated attacker could inject malicious CSV expression to the affected device.
|
CWE-74
Injection
|
CVE-2017-15313
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251692
|
5.4 |
MEDIUM
Network
|
huawei
|
smartcare
|
Huawei SmartCare V200R003C10 has a stored XSS (cross-site scripting) vulnerability in the dashboard module. A remote authenticated attacker could exploit this vulnerability to inject malicious script…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15312
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251693
|
6.5 |
MEDIUM
Network
|
huawei
|
ireader
|
Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vulnerability to delete specific files from the SD c…
|
CWE-20
Improper Input Validation
|
CVE-2017-15310
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251694
|
7.5 |
HIGH
Network
|
huawei
|
rp200_firmware te30_firmware te40_firmware te50_firmware te60_firmware
|
RP200 V500R002C00, V600R006C00; TE30 V100R001C10, V500R002C00, V600R006C00; TE40 V500R002C00, V600R006C00; TE50 V500R002C00, V600R006C00; TE60 V100R001C10, V500R002C00, V600R006C00 have an out-of-bou…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-15318
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251695
|
7.5 |
HIGH
Network
|
huawei
|
ar120-s_firmware ar1200_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200_firmware ar200-s_firmware ar2200_firmware ar2200-s_firmware ar320…
|
AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR1200-S V200R006C10, V200R007C00, V200R0…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-15317
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251696
|
8.8 |
HIGH
Adjacent
|
huawei
|
mate_10_firmware mate_10_pro_firmware mate_9_firmware mate_9_pro_firmware
|
The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15311
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251697
|
7.1 |
HIGH
Network
|
huawei
|
ireader
|
Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious f…
|
CWE-22
Path Traversal
|
CVE-2017-15309
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251698
|
8.8 |
HIGH
Network
|
huawei
|
ireader
|
Huawei iReader app before 8.0.2.301 has an input validation vulnerability due to insufficient validation on the URL used for loading network data. An attacker can control app access and load maliciou…
|
CWE-20
Improper Input Validation
|
CVE-2017-15308
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251699
|
2.3 |
LOW
Local
|
huawei
|
honor_8_firmware
|
Huawei Honor 8 smartphone with software versions earlier than FRD-L04C567B389 and earlier than FRD-L14C567B389 have a permission control vulnerability due to improper authorization configuration on s…
|
NVD-CWE-noinfo
|
CVE-2017-15307
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251700
|
5.7 |
MEDIUM
Adjacent
|
symantec
|
messaging_gateway
|
Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stor…
|
CWE-22
Path Traversal
|
CVE-2017-15532
|
2024-11-21 12:14 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|