|
252461
|
6.1 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited r…
|
CWE-601
Open Redirect
|
CVE-2017-14358
|
2024-11-21 12:12 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252462
|
6.1 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
A Reflected and Stored Cross-Site Scripting (XSS) vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could …
|
CWE-79
Cross-site Scripting
|
CVE-2017-14357
|
2024-11-21 12:12 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252463
|
9.8 |
CRITICAL
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQ…
|
CWE-89
SQL Injection
|
CVE-2017-14356
|
2024-11-21 12:12 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252464
|
6.1 |
MEDIUM
Network
|
emc
|
rsa_authentication_manager
|
EMC RSA Authentication Manager 8.2 SP1 P4 and earlier contains a reflected cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14373
|
2024-11-21 12:12 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252465
|
6.5 |
MEDIUM
Network
|
fortinet
|
fortios
|
A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to…
|
CWE-20
Improper Input Validation
|
CVE-2017-14182
|
2024-11-21 12:12 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252466
|
8.1 |
HIGH
Network
|
extremenetworks
|
extremexos
|
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values.
|
NVD-CWE-noinfo
|
CVE-2017-14332
|
2024-11-21 12:12 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252467
|
6.7 |
MEDIUM
Local
|
extremenetworks
|
extremexos
|
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell.
|
NVD-CWE-noinfo
|
CVE-2017-14331
|
2024-11-21 12:12 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252468
|
6.7 |
MEDIUM
Local
|
extremenetworks
|
extremexos
|
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.
|
CWE-269
Improper Privilege Management
|
CVE-2017-14330
|
2024-11-21 12:12 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252469
|
6.7 |
MEDIUM
Local
|
extremenetworks
|
extremexos
|
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell.
|
CWE-269
Improper Privilege Management
|
CVE-2017-14329
|
2024-11-21 12:12 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252470
|
7.5 |
HIGH
Network
|
extremenetworks
|
extremexos
|
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14328
|
2024-11-21 12:12 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|