|
250091
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value fo…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-2647
|
2024-11-21 12:23 |
2017-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250092
|
8.8 |
HIGH
Network
|
siemens
|
ruggedcom_rox_i
|
Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or change configuration…
|
CWE-287
Improper Authentication
|
CVE-2017-2689
|
2024-11-21 12:23 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250093
|
8.8 |
HIGH
Network
|
siemens
|
ruggedcom_rox_i
|
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the target…
|
CWE-352
Origin Validation Error
|
CVE-2017-2688
|
2024-11-21 12:23 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250094
|
6.1 |
MEDIUM
Network
|
siemens
|
ruggedcom_rox_i
|
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site Scripting attacks if an unsuspecting user is induc…
|
CWE-79
Cross-site Scripting
|
CVE-2017-2687
|
2024-11-21 12:23 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250095
|
6.5 |
MEDIUM
Network
|
siemens
|
ruggedcom_rox_i
|
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and access sensitive informat…
|
CWE-200
Information Exposure
|
CVE-2017-2686
|
2024-11-21 12:23 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250096
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.
|
CWE-79
Cross-site Scripting
|
CVE-2017-2645
|
2024-11-21 12:23 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250097
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.x, XSS can occur via evidence of prior learning.
|
CWE-79
Cross-site Scripting
|
CVE-2017-2644
|
2024-11-21 12:23 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250098
|
5.3 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.2.x, global search displays user names for unauthenticated users.
|
CWE-200
Information Exposure
|
CVE-2017-2643
|
2024-11-21 12:23 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250099
|
9.8 |
CRITICAL
Network
|
moodle
|
moodle
|
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
|
CWE-89
SQL Injection
|
CVE-2017-2641
|
2024-11-21 12:23 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250100
|
7.0 |
HIGH
Local
|
linux debian
|
linux_kernel debian_linux
|
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
|
CWE-362 CWE-415
Race Condition Double Free
|
CVE-2017-2636
|
2024-11-21 12:23 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|