|
247911
|
9.8 |
CRITICAL
Network
|
gigabyte
|
gb-bsi7h-6500_firmware gb-bxi7-5775_firmware
|
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary m…
|
CWE-347 CWE-311
Improper Verification of Cryptographic Signature Missing Encryption of Sensitive Data
|
CVE-2017-3198
|
2024-11-21 12:25 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247912
|
9.8 |
CRITICAL
Network
|
gigabyte
|
gb-bsi7h-6500_firmware gb-bxi7-5775_firmware
|
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not…
|
CWE-20
Improper Input Validation
|
CVE-2017-3197
|
2024-11-21 12:25 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247913
|
9.8 |
CRITICAL
Network
|
themidnightcoders
|
weborb_for_java
|
The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. I…
|
CWE-611
XXE
|
CVE-2017-3208
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247914
|
9.8 |
CRITICAL
Network
|
themidnightcoders
|
weborb_for_java
|
The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externalizable rather than the AMF3 specification's recommen…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3207
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247915
|
9.8 |
CRITICAL
Network
|
exadel
|
flamingo
|
The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If t…
|
CWE-611
XXE
|
CVE-2017-3206
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247916
|
8.1 |
HIGH
Network
|
pivotal
|
spring-flex
|
The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExt…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3203
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247917
|
8.1 |
HIGH
Network
|
exadel
|
flamingo_amf-serializer
|
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class instances from java.io.Externalizable rather than the AMF3 specification's recomme…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3201
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247918
|
8.1 |
HIGH
Network
|
graniteds
|
graniteds
|
The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExte…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3199
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247919
|
9.8 |
CRITICAL
Network
|
exadel
|
flamingo
|
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes via their public parameter-less constructor and su…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3202
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247920
|
8.1 |
HIGH
Network
|
graniteds
|
graniteds
|
The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitr…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3200
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|