|
249681
|
5.3 |
MEDIUM
Network
|
ruby-lang debian
|
ruby debian_linux
|
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTT…
|
CWE-113
HTTP Response Splitting
|
CVE-2017-17742
|
2024-11-21 12:18 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249682
|
7.8 |
HIGH
Local
|
google
|
android
|
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in a power driver ioctl handler, an …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-17770
|
2024-11-21 12:18 |
2018-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249683
|
7.8 |
HIGH
Local
|
google
|
android
|
In msm_isp_prepare_v4l2_buf in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-02-12, an array out of bounds can occur.
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-17771
|
2024-11-21 12:18 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249684
|
5.5 |
MEDIUM
Local
|
google
|
android
|
Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.
|
CWE-200
Information Exposure
|
CVE-2017-17769
|
2024-11-21 12:18 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249685
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received from firmware is not properly validated so that an integer …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-17766
|
2024-11-21 12:18 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249686
|
8.8 |
HIGH
Network
|
bose
|
soundtouch
|
Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket Protocol.
|
NVD-CWE-noinfo
|
CVE-2017-17751
|
2024-11-21 12:18 |
2018-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249687
|
5.4 |
MEDIUM
Network
|
bose
|
soundtouch
|
Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17750
|
2024-11-21 12:18 |
2018-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249688
|
5.4 |
MEDIUM
Network
|
bose
|
soundtouch
|
Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17749
|
2024-11-21 12:18 |
2018-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249689
|
9.8 |
CRITICAL
Network
|
kentico
|
kentico_cms
|
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashb…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2017-17736
|
2024-11-21 12:18 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249690
|
6.7 |
MEDIUM
Local
|
ucopia
|
wireless_appliance_firmware
|
Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5.1.x before 5.1.11 allows authenticated remote att…
|
CWE-287
Improper Authentication
|
CVE-2017-17743
|
2024-11-21 12:18 |
2018-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|