|
255191
|
5.4 |
MEDIUM
Network
|
synology
|
photo_station
|
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id par…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12072
|
2024-11-21 12:08 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255192
|
8.8 |
HIGH
Network
|
mt4
|
senhasegura
|
A Session Fixation Vulnerability exists in the MT4 Networks SenhaSegura Web Application 2.2.23.8 via login_if.php.
|
CWE-384
Session Fixation
|
CVE-2017-11562
|
2024-11-21 12:08 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255193
|
6.5 |
MEDIUM
Network
|
microsoft
|
office
|
Microsoft Office 2016 Click-to-Run (C2R) allows an information disclosure vulnerability due to the way Microsoft Office enforces DRM copy/paste permissions, aka "Microsoft Office Information Disclosu…
|
CWE-200
Information Exposure
|
CVE-2017-11939
|
2024-11-21 12:08 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255194
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_enterprise_server
|
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability".
|
CWE-20
Improper Input Validation
|
CVE-2017-11936
|
2024-11-21 12:08 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255195
|
7.8 |
HIGH
Local
|
microsoft
|
office
|
Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11935
|
2024-11-21 12:08 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255196
|
5.5 |
MEDIUM
Local
|
microsoft
|
office
|
Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory, aka "Micros…
|
CWE-200
Information Exposure
|
CVE-2017-11934
|
2024-11-21 12:08 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255197
|
8.1 |
HIGH
Network
|
microsoft
|
exchange_server
|
Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofi…
|
CWE-20
Improper Input Validation
|
CVE-2017-11932
|
2024-11-21 12:08 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255198
|
7.5 |
HIGH
Network
|
microsoft
|
chakracore internet_explorer
|
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11930
|
2024-11-21 12:08 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255199
|
5.3 |
MEDIUM
Network
|
microsoft
|
internet_explorer
|
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Serv…
|
CWE-200
Information Exposure
|
CVE-2017-11906
|
2024-11-21 12:08 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255200
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_10 windows_server_2016
|
Device Guard in Windows 10 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way untrusted files are handled, a…
|
NVD-CWE-noinfo
|
CVE-2017-11899
|
2024-11-21 12:08 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|