|
251911
|
7.8 |
HIGH
Local
|
hashicorp
|
vagrant_vmware_fusion
|
The vagrant update process in Hashicorp vagrant-vmware-fusion 5.0.2 through 5.0.4 allows local users to steal root privileges via a crafted update request when no updates are available.
|
CWE-362
Race Condition
|
CVE-2017-16512
|
2024-11-21 12:16 |
2018-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251912
|
6.8 |
MEDIUM
Physics
|
meco
|
usb_memory_stick_with_fingerprint_firwmare
|
An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data access can be bypassed. An attacker with physical acces…
|
CWE-287
Improper Authentication
|
CVE-2017-16242
|
2024-11-21 12:16 |
2018-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251913
|
8.8 |
HIGH
Network
|
synology
|
photo_station
|
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes vi…
|
CWE-20
Improper Input Validation
|
CVE-2017-16772
|
2024-11-21 12:16 |
2018-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251914
|
6.1 |
MEDIUM
Network
|
synology
|
photo_station
|
Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16771
|
2024-11-21 12:16 |
2018-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251915
|
7.8 |
HIGH
Local
|
deltaww
|
delta_industrial_automation_screen_editor
|
A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Stack-based buffer overflow vulnerabilities caused by p…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16751
|
2024-11-21 12:16 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251916
|
7.8 |
HIGH
Local
|
deltaww
|
delta_industrial_automation_screen_editor
|
A Use-after-Free issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files could exploit a use-after-free vulnerab…
|
CWE-416
Use After Free
|
CVE-2017-16749
|
2024-11-21 12:16 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251917
|
7.8 |
HIGH
Local
|
deltaww
|
delta_industrial_automation_screen_editor
|
An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write out…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-16747
|
2024-11-21 12:16 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251918
|
7.8 |
HIGH
Local
|
deltaww
|
delta_industrial_automation_screen_editor
|
A Type Confusion issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. An access of resource using incompatible type ('type confusion') vul…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2017-16745
|
2024-11-21 12:16 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251919
|
8.8 |
HIGH
Network
|
mitel
|
st14.2
|
A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST requ…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-16251
|
2024-11-21 12:16 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251920
|
5.3 |
MEDIUM
Network
|
mitel
|
st14.2
|
A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could be used to identify valid user ids and associated…
|
CWE-200
Information Exposure
|
CVE-2017-16250
|
2024-11-21 12:16 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|