|
254941
|
4.3 |
MEDIUM
Network
|
cisco
|
expressway telepresence_video_communication_server telepresence_conductor
|
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, r…
|
CWE-20
Improper Input Validation
|
CVE-2017-12287
|
2024-11-21 12:09 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254942
|
5.5 |
MEDIUM
Local
|
cisco
|
webex_meeting_center jabber
|
A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure o…
|
CWE-20
Improper Input Validation
|
CVE-2017-12286
|
2024-11-21 12:09 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254943
|
5.3 |
MEDIUM
Network
|
cisco
|
prime_network_analysis_module
|
A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Travers…
|
CWE-22 CWE-20
Path Traversal Improper Input Validation
|
CVE-2017-12285
|
2024-11-21 12:09 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254944
|
5.5 |
MEDIUM
Local
|
cisco
|
jabber
|
A vulnerability in the web interface of Cisco Jabber for Windows Client could allow an authenticated, local attacker to retrieve user profile information, which could lead to the disclosure of confid…
|
CWE-200
Information Exposure
|
CVE-2017-12284
|
2024-11-21 12:09 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254945
|
6.1 |
MEDIUM
Network
|
cisco
|
ios_xe
|
A vulnerability in the web framework code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface o…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12272
|
2024-11-21 12:09 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254946
|
7.5 |
HIGH
Network
|
cisco
|
spa_501g_firmware spa_502g_firmware spa_504g_firmware spa_508g_firmware spa_509g_firmware spa_512g_firmware spa_514g_firmware spa_525g_firmware
|
A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA50x, SPA51x, and SPA52x Series IP Phones could allow an unauthenticated, remote att…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12260
|
2024-11-21 12:09 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254947
|
7.5 |
HIGH
Network
|
cisco
|
small_business_ip_phone_firmware
|
A vulnerability in the implementation of Session Initiation Protocol (SIP) functionality in Cisco Small Business SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause an af…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12259
|
2024-11-21 12:09 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254948
|
9.9 |
CRITICAL
Network
|
cisco
|
cloud_services_platform_2100
|
A vulnerability in the web console of the Cisco Cloud Services Platform (CSP) 2100 could allow an authenticated, remote attacker to interact maliciously with the services or virtual machines (VMs) op…
|
CWE-287
Improper Authentication
|
CVE-2017-12251
|
2024-11-21 12:09 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254949
|
9.8 |
CRITICAL
Network
|
apache redhat debian canonical
|
solr jboss_enterprise_application_platform debian_linux ubuntu_linux
|
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener …
|
CWE-611
XXE
|
CVE-2017-12629
|
2024-11-21 12:09 |
2017-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254950
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.13.5 does not properly consider that a key may be possessed but negatively insta…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-12192
|
2024-11-21 12:09 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|