|
251801
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, PKCS7 padding is not supported by the crypto storage APIs.
|
NVD-CWE-noinfo
|
CVE-2017-14906
|
2024-11-21 12:13 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251802
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to the lack of a range check on the array index into the WMI descriptor pool, arbit…
|
CWE-129
Improper Validation of Array Index
|
CVE-2017-14889
|
2024-11-21 12:13 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251803
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the processing of messages of type eWNI_SME_MODIFY_ADDITIONAL_IES, an integer overfl…
|
CWE-119 CWE-190
Incorrect Access of Indexable Resource ('Range Error') Integer Overflow or Wraparound
|
CVE-2017-14887
|
2024-11-21 12:13 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251804
|
7.5 |
HIGH
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing VENDOR specific action frame in the function lim_process_action_vendor…
|
CWE-119 CWE-200
Incorrect Access of Indexable Resource ('Range Error') Information Exposure
|
CVE-2017-14882
|
2024-11-21 12:13 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251805
|
7.5 |
HIGH
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a length variable which is used to copy data has a size of only 8 bits and can be excee…
|
CWE-20
Improper Input Validation
|
CVE-2017-14878
|
2024-11-21 12:13 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251806
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, wma_unified_link_peer_stats_event_handler function has a variable num_rates which repre…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14885
|
2024-11-21 12:13 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251807
|
6.1 |
MEDIUM
Network
|
netiq
|
access_manager
|
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.
|
CWE-601
Open Redirect
|
CVE-2017-14802
|
2024-11-21 12:13 |
2018-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251808
|
6.1 |
MEDIUM
Network
|
netiq
|
access_manager
|
Reflected XSS in the NetIQ Access Manager before 4.3.3 allowed attackers to reflect back xss into the called page using the url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14801
|
2024-11-21 12:13 |
2018-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251809
|
5.3 |
MEDIUM
Network
|
suse opensuse
|
linux_enterprise_software_development_kit leap
|
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroot…
|
CWE-20
Improper Input Validation
|
CVE-2017-14804
|
2024-11-21 12:13 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251810
|
6.1 |
MEDIUM
Network
|
netiq
|
access_manager
|
A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter of the policy editor could allowed code injection into pages of authenticated us…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14800
|
2024-11-21 12:13 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|