|
252281
|
6.1 |
MEDIUM
Network
|
phpcaptcha
|
securimage
|
HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_USER_AGENT'] parameter to example_form.ajax.php or e…
|
CWE-94
Code Injection
|
CVE-2017-14077
|
2024-11-21 12:12 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252282
|
7.2 |
HIGH
Network
|
philips
|
xcelera intellispace_cardiovascular
|
The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-14111
|
2024-11-21 12:12 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252283
|
7.5 |
HIGH
Network
|
moxa
|
nport_5110_firmware nport_5130_firmware nport_5150_firmware
|
A Resource Exhaustion issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Ver…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-14028
|
2024-11-21 12:12 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252284
|
8.8 |
HIGH
Network
|
libbpg_project
|
libbpg
|
The restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.7 and other products, miscalculates a memcpy destination address, which allows remote attackers to cause a denial…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-14034
|
2024-11-21 12:12 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252285
|
7.8 |
HIGH
Local
|
pivotal_software
|
grootfs
|
Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the grootfs volume cache. For example, this could allow an…
|
CWE-20
Improper Input Validation
|
CVE-2017-14388
|
2024-11-21 12:12 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252286
|
7.5 |
HIGH
Network
|
hp
|
content_manager
|
A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability could be remotely exploited to allow Denial of Service (DoS).
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-14360
|
2024-11-21 12:12 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252287
|
7.8 |
HIGH
Local
|
trihedral
|
vtscada
|
An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and write to the file system of the target machine.
|
CWE-269
Improper Privilege Management
|
CVE-2017-14031
|
2024-11-21 12:12 |
2017-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252288
|
7.8 |
HIGH
Local
|
trihedral
|
vtscada
|
An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program will execute specially crafted malicious dll files placed on the target machine.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-14029
|
2024-11-21 12:12 |
2017-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252289
|
5.4 |
MEDIUM
Network
|
hp
|
performance_center
|
A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The vulnerability could be remotely exploited to allow cross-site scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14359
|
2024-11-21 12:12 |
2017-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252290
|
7.8 |
HIGH
Local
|
emc
|
appsync
|
EMC AppSync Server prior to 3.5.0.1 contains database accounts with hardcoded passwords that could potentially be exploited by malicious users to compromise the affected system.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-14376
|
2024-11-21 12:12 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|