|
256171
|
7.8 |
HIGH
Local
|
google
|
android
|
A elevation of privilege vulnerability in the Android framework (wi-fi service). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207928.
|
CWE-119 CWE-20
Incorrect Access of Indexable Resource ('Range Error') Improper Input Validation
|
CVE-2017-0712
|
2024-11-21 12:03 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256172
|
7.5 |
HIGH
Network
|
progress
|
mixlib-archive
|
Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries
|
CWE-22
Path Traversal
|
CVE-2017-1000026
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256173
|
7.5 |
HIGH
Network
|
gnome
|
epiphany
|
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfi…
|
CWE-200
Information Exposure
|
CVE-2017-1000025
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256174
|
7.5 |
HIGH
Network
|
gnome
|
shotwell
|
Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-1000024
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256175
|
5.4 |
MEDIUM
Network
|
logicaldoc
|
logicaldoc
|
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000023
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256176
|
8.8 |
HIGH
Network
|
logicaldoc
|
logicaldoc
|
LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-1000022
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256177
|
8.8 |
HIGH
Network
|
logicaldoc
|
logicaldoc
|
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
|
CWE-611
XXE
|
CVE-2017-1000021
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256178
|
9.8 |
CRITICAL
Network
|
ecos
|
embedded_web_servers
|
SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by Multiple Routers and Home devices, while sending S…
|
CWE-287
Improper Authentication
|
CVE-2017-1000020
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256179
|
7.5 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name
|
CWE-20
Improper Input Validation
|
CVE-2017-1000018
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256180
|
8.8 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-1000017
|
2024-11-21 12:03 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|