|
255881
|
9.8 |
CRITICAL
Network
|
recurly
|
recurly_client_.net
|
The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.Escape…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-0907
|
2024-11-21 12:03 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255882
|
9.8 |
CRITICAL
Network
|
recurly
|
recurly_client_python
|
The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-0906
|
2024-11-21 12:03 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255883
|
9.8 |
CRITICAL
Network
|
recurly
|
recurly_client_ruby
|
The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the "Re…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-0905
|
2024-11-21 12:03 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255884
|
8.1 |
HIGH
Network
|
private_address_check_project
|
private_address_check
|
The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, s…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2017-0904
|
2024-11-21 12:03 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255885
|
9.8 |
CRITICAL
Network
|
thoughtbot
|
paperclip
|
Paperclip ruby gem version 3.1.4 and later suffers from a Server-SIde Request Forgery (SSRF) vulnerability in the Paperclip::UriAdapter class. Attackers may be able to access information about intern…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-0889
|
2024-11-21 12:03 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255886
|
9.8 |
CRITICAL
Network
|
rubygems debian canonical redhat
|
rubygems debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterp…
|
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-0903
|
2024-11-21 12:03 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255887
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An elevation of privilege vulnerability in the Motorola bootloader. Product: Android. Versions: Android kernel. Android ID: A-62345044.
|
NVD-CWE-noinfo
|
CVE-2017-0829
|
2024-11-21 12:03 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255888
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An elevation of privilege vulnerability in the Huawei bootloader. Product: Android. Versions: Android kernel. Android ID: A-34622855.
|
NVD-CWE-noinfo
|
CVE-2017-0828
|
2024-11-21 12:03 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255889
|
7.8 |
HIGH
Local
|
google
|
android
|
An elevation of privilege vulnerability in the MediaTek soc driver. Product: Android. Versions: Android kernel. Android ID: A-62539960. References: M-ALPS03353876, M-ALPS03353861, M-ALPS03353869, M-A…
|
NVD-CWE-noinfo
|
CVE-2017-0827
|
2024-11-21 12:03 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255890
|
7.8 |
HIGH
Local
|
google
|
android
|
An elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-34949781.
|
NVD-CWE-noinfo
|
CVE-2017-0826
|
2024-11-21 12:03 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|