|
247661
|
6.1 |
MEDIUM
Network
|
trihedral
|
vtscada
|
A Cross-Site Scripting issue was discovered in Trihedral VTScada Versions prior to 11.2.26. A cross-site scripting vulnerability may allow JavaScript code supplied by the attacker to execute within t…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6053
|
2024-11-21 12:28 |
2017-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247662
|
9.8 |
CRITICAL
Network
|
ecava
|
integraxor
|
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remot…
|
CWE-89
SQL Injection
|
CVE-2017-6050
|
2024-11-21 12:28 |
2017-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247663
|
7.5 |
HIGH
Network
|
trihedral
|
vtscada
|
An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application to unauthenticated users. These files may contain…
|
CWE-200
Information Exposure
|
CVE-2017-6045
|
2024-11-21 12:28 |
2017-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247664
|
7.5 |
HIGH
Network
|
trihedral
|
vtscada
|
A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit the amount of resources that are utilized by an at…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-6043
|
2024-11-21 12:28 |
2017-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247665
|
6.5 |
MEDIUM
Network
|
intel
|
active_management_technology_firmware
|
Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remot…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2017-5697
|
2024-11-21 12:28 |
2017-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247666
|
9.8 |
CRITICAL
Network
|
red5
|
media_server
|
The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serializ…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-5878
|
2024-11-21 12:28 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247667
|
7.5 |
HIGH
Network
|
apache
|
tomcat
|
The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwa…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2017-5664
|
2024-11-21 12:28 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247668
|
5.3 |
MEDIUM
Network
|
phoenixbroadband
|
poweragent_sc3_bms_firmware
|
A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all versions prior to v6.87. Use of a hard-coded password may allow unauthorized access to the device.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-6039
|
2024-11-21 12:28 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247669
|
6.7 |
MEDIUM
Local
|
intel
|
solid_state_drive_toolbox
|
There is an escalation of privilege vulnerability in the Intel Solid State Drive Toolbox versions before 3.4.5 which allow a local administrative attacker to load and execute arbitrary code.
|
NVD-CWE-noinfo
|
CVE-2017-5688
|
2024-11-21 12:28 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247670
|
6.8 |
MEDIUM
Network
|
apache
|
knox
|
For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in es…
|
CWE-346
Origin Validation Error
|
CVE-2017-5646
|
2024-11-21 12:28 |
2017-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|