|
249841
|
8.8 |
HIGH
Network
|
apple
|
iphone_os safari
|
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute ar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-2496
|
2024-11-21 12:23 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249842
|
6.5 |
MEDIUM
Network
|
apple
|
iphone_os safari
|
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "Safari" component. It allows remote attackers to cause a de…
|
CWE-20
Improper Input Validation
|
CVE-2017-2495
|
2024-11-21 12:23 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249843
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-2494
|
2024-11-21 12:23 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249844
|
7.8 |
HIGH
Local
|
softbank
|
primedrive_desktop_application
|
Untrusted search path vulnerability in Installer for PrimeDrive Desktop Application version 1.4.4 and earlier allows remote attackers to execute arbitrary code via a specially crafted executable file…
|
CWE-426
Untrusted Search Path
|
CVE-2017-2167
|
2024-11-21 12:23 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249845
|
6.1 |
MEDIUM
Network
|
n-i-agroinformatics
|
soy_cms
|
Cross-site scripting vulnerability in SOY CMS with installer 1.8.12 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2017-2164
|
2024-11-21 12:23 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249846
|
7.5 |
HIGH
Network
|
n-i-agroinformatics
|
soy_cms
|
Directory traversal vulnerability in SOY CMS Ver.1.8.1 to Ver.1.8.12 allows authenticated attackers to read arbitrary files via shop_id.
|
CWE-22
Path Traversal
|
CVE-2017-2163
|
2024-11-21 12:23 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249847
|
7.3 |
HIGH
Local
|
jpki
|
the_public_certification_service_for_individuals
|
Untrusted search path vulnerability in installers for The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.1 and earlier, The Public Certificatio…
|
CWE-426
Untrusted Search Path
|
CVE-2017-2157
|
2024-11-21 12:23 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249848
|
6.5 |
MEDIUM
Adjacent
|
siemens
|
simatic_cp_343-1_std_firmware simatic_cp_343-1_lean_firmware simatic_cp_343-1_adv_firmware simatic_cp_443-1_std_firmware simatic_cp_443-1_adv_firmware simatic_cp_443-1_opc-ua_firmware<…
|
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to re…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-2681
|
2024-11-21 12:23 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249849
|
6.5 |
MEDIUM
Adjacent
|
siemens
|
simatic_cp_343-1_std_firmware simatic_cp_343-1_lean_firmware simatic_cp_343-1_adv_firmware simatic_cp_443-1_std_firmware simatic_cp_443-1_adv_firmware simatic_cp_443-1_opc-ua_firmware<…
|
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the sys…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-2680
|
2024-11-21 12:23 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249850
|
7.8 |
HIGH
Local
|
vivaldi
|
vivaldi_installer_for_windows
|
Untrusted search path vulnerability in Vivaldi installer for Windows prior to version 1.7.735.48 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified…
|
CWE-426
Untrusted Search Path
|
CVE-2017-2156
|
2024-11-21 12:23 |
2017-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|