|
247961
|
8.1 |
HIGH
Network
|
meetcircle
|
circle_with_disney_firmware
|
An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A specially crafted token can bypass the authentication routine of the Apid b…
|
CWE-287
Improper Authentication
|
CVE-2017-2914
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247962
|
5.9 |
MEDIUM
Network
|
meetcircle
|
circle_with_disney_firmware
|
An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific domain names can cause the Bluecoat library to accept a different certificate t…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-2913
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247963
|
5.9 |
MEDIUM
Network
|
meetcircle
|
circle_with_disney_firmware
|
An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the goclient daemon to accep…
|
CWE-297
Improper Validation of Certificate with Host Mismatch
|
CVE-2017-2912
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247964
|
5.9 |
MEDIUM
Network
|
meetcircle
|
circle_with_disney_firmware
|
An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the rclient daemon to accept…
|
CWE-297
Improper Validation of Certificate with Host Mismatch
|
CVE-2017-2911
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247965
|
7.5 |
HIGH
Network
|
cesanta
|
mongoose
|
An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request can cause an infinite loop resulting in high CPU usage and D…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-2909
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247966
|
7.5 |
HIGH
Network
|
meetcircle
|
circle_with_disney_firmware
|
An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Disney. Specially crafted network packets can cause an unsigned firmware to be in…
|
CWE-362
Race Condition
|
CVE-2017-2898
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247967
|
8.2 |
HIGH
Network
|
cesanta
|
mongoose
|
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bou…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-2895
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247968
|
9.8 |
CRITICAL
Network
|
cesanta
|
mongoose
|
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-2894
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247969
|
7.5 |
HIGH
Network
|
cesanta
|
mongoose
|
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-2893
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247970
|
9.8 |
CRITICAL
Network
|
cesanta
|
mongoose
|
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-2892
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|