|
250831
|
7.8 |
HIGH
Local
|
we-con
|
levistudio_hmi_editor_firmware
|
An issue was discovered in WECON Technology LEVI Studio HMI Editor v1.8.29 and prior. Specially-crafted malicious files may be able to cause stack-based buffer overflow vulnerabilities, which may all…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16739
|
2024-11-21 12:16 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250832
|
7.8 |
HIGH
Local
|
we-con
|
levistudio_hmi_editor_firmware
|
An issue was discovered in WECON Technology LEVI Studio HMI Editor v1.8.29 and prior. A specially-crafted malicious file may be able to cause a heap-based buffer overflow vulnerability when opened by…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16737
|
2024-11-21 12:16 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250833
|
9.8 |
CRITICAL
Network
|
phoenixcontact
|
fl_switch_3005_firmware fl_switch_3005t_firmware fl_switch_3004t-fx_firmware fl_switch_3004t-fx_st_firmware fl_switch_3008_firmware fl_switch_3008t_firmware fl_switch_3006t-2fx_firm…
|
An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able t…
|
CWE-863
Incorrect Authorization
|
CVE-2017-16743
|
2024-11-21 12:16 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250834
|
5.3 |
MEDIUM
Network
|
phoenixcontact
|
fl_switch_3005_firmware fl_switch_3005t_firmware fl_switch_3004t-fx_firmware fl_switch_3004t-fx_st_firmware fl_switch_3008_firmware fl_switch_3008t_firmware fl_switch_3006t-2fx_firm…
|
An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to …
|
CWE-200
Information Exposure
|
CVE-2017-16741
|
2024-11-21 12:16 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250835
|
7.5 |
HIGH
Network
|
advantech
|
webaccess
|
An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attacker to upload arbitrary files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-16736
|
2024-11-21 12:16 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250836
|
6.5 |
MEDIUM
Network
|
advantech
|
webaccess
|
A use-after-free issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows an unauthenticated attacker to specify an arbitrary address.
|
CWE-416
Use After Free
|
CVE-2017-16732
|
2024-11-21 12:16 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250837
|
6.1 |
MEDIUM
Network
|
websitebaker
|
websitebaker
|
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16514
|
2024-11-21 12:16 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250838
|
10.0 |
CRITICAL
Network
|
rockwellautomation
|
1766-l32bxba_firmware 1766-l32awa_firmware 1766-l32bxb_firmware 1766-l32bwaa_firmware 1766-l32awaa_firmware 1766-l32bwa_firmware
|
A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. The stack-based buffer overflow vulnerability has …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16740
|
2024-11-21 12:16 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250839
|
8.8 |
HIGH
Network
|
xplico
|
xplico
|
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. NOTE: this issue can be exploited without authentic…
|
CWE-78
OS Command
|
CVE-2017-16666
|
2024-11-21 12:16 |
2018-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250840
|
7.5 |
HIGH
Network
|
advantech
|
webaccess
|
An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows some inputs that may cause the program to crash.
|
CWE-20
Improper Input Validation
|
CVE-2017-16753
|
2024-11-21 12:16 |
2018-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|