|
247641
|
7.0 |
HIGH
Local
|
waves
|
maxxaudio
|
Waves MaxxAudio, as installed on Dell laptops, adds a "WavesSysSvc" Windows service with File Version 1.1.6.0. This service has a vulnerability known as Unquoted Service Path. This could potentially …
|
NVD-CWE-noinfo
|
CVE-2017-6005
|
2024-11-21 12:28 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247642
|
7.5 |
HIGH
Network
|
apache
|
impala
|
During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when the cluster was configured to use TLS. The port in…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-5652
|
2024-11-21 12:28 |
2017-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247643
|
9.8 |
CRITICAL
Network
|
apache
|
impala
|
It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (…
|
CWE-287
Improper Authentication
|
CVE-2017-5640
|
2024-11-21 12:28 |
2017-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247644
|
8.8 |
HIGH
Network
|
bestpractical
|
request_tracker
|
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute a…
|
CWE-20
Improper Input Validation
|
CVE-2017-5944
|
2024-11-21 12:28 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247645
|
8.8 |
HIGH
Network
|
bestpractical
|
request_tracker
|
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site request forgery (CSRF) verification tokens…
|
CWE-352
Origin Validation Error
|
CVE-2017-5943
|
2024-11-21 12:28 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247646
|
7.5 |
HIGH
Network
|
sierra_wireless
|
airlink_raven_xe_firmware airlink_raven_xt_firmware
|
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive informati…
|
CWE-200
Information Exposure
|
CVE-2017-6046
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247647
|
9.8 |
CRITICAL
Network
|
sierra_wireless
|
airlink_raven_xe_firmware airlink_raven_xt_firmware
|
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-6044
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247648
|
8.8 |
HIGH
Network
|
sierra_wireless
|
airlink_raven_xe_firmware airlink_raven_xt_firmware
|
A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify…
|
CWE-352
Origin Validation Error
|
CVE-2017-6042
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247649
|
5.3 |
MEDIUM
Network
|
belden_hirschmann
|
gecko_lite_managed_switch_firmware
|
An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive information can be obtained anonymously.
|
CWE-200
Information Exposure
|
CVE-2017-6040
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247650
|
7.1 |
HIGH
Network
|
belden_hirschmann
|
gecko_lite_managed_switch_firmware
|
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests wer…
|
CWE-352
Origin Validation Error
|
CVE-2017-6038
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|