|
250151
|
5.7 |
MEDIUM
Network
|
huawei
|
dp300_firmware rp200_firmware te30_firmware te50_firmware te60_firmware vp9660_firmware
|
Huawei DP300 V500R002C00; RP200 V500R002C00; V600R006C00; TE30 V100R001C10; V600R006C00; TE50 V600R006C00; TE60 V100R001C10; V500R002C00; V600R006C00; VP9660 V500R002C10 have an DoS vulnerability due…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-17131
|
2024-11-21 12:17 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250152
|
5.9 |
MEDIUM
Network
|
cavium cisco
|
nitrox_v_ssl_sdk nitrox_ssl_sdk turbossl_sdk octeon_ssl_sdk octeon_sdk webex_meetings webex_conect_im ace4710_application_control_engine_firmware ace30_application_control_eng…
|
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT att…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2017-17428
|
2024-11-21 12:17 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250153
|
5.5 |
MEDIUM
Local
|
foxitsoftware
|
mobilepdf
|
A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs by abusing the URL + escape character during a Wi-Fi transfer, which could be exploited by attack…
|
CWE-22
Path Traversal
|
CVE-2017-16814
|
2024-11-21 12:17 |
2018-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250154
|
5.5 |
MEDIUM
Local
|
foxitsoftware
|
mobilepdf
|
A denial-of-service issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs when a user uploads a file that includes a hexadecimal Unicode character in the "filename" paramete…
|
CWE-20
Improper Input Validation
|
CVE-2017-16813
|
2024-11-21 12:17 |
2018-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250155
|
5.9 |
MEDIUM
Network
|
mahara
|
mahara
|
Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HT…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-17455
|
2024-11-21 12:17 |
2018-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250156
|
5.4 |
MEDIUM
Network
|
mahara
|
mahara
|
Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be di…
|
CWE-79
Cross-site Scripting
|
CVE-2017-17454
|
2024-11-21 12:17 |
2018-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250157
|
7.5 |
HIGH
Network
|
photo\ video_locker-calculator_project
|
photo\ video_locker-calculator
|
The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb ba…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2017-16835
|
2024-11-21 12:17 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250158
|
9.8 |
CRITICAL
Network
|
apexis
|
apm-h803-mpc_firmware
|
An issue was discovered in Apexis APM-H803-MPC software, as used with many different models of IP Camera. An unprotected CGI method inside the web application permits an unauthenticated user to bypas…
|
NVD-CWE-noinfo
|
CVE-2017-17101
|
2024-11-21 12:17 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250159
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central
|
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration polici…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2017-16924
|
2024-11-21 12:17 |
2018-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250160
|
8.8 |
HIGH
Adjacent
|
huawei
|
lon-al00b_firmware
|
Bluetooth module in some Huawei mobile phones with software LON-AL00BC00B229 and earlier versions has a buffer overflow vulnerability. Due to insufficient input validation, an unauthenticated attacke…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17285
|
2024-11-21 12:17 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|