|
247141
|
9.8 |
CRITICAL
Network
|
postgresql debian
|
postgresql debian_linux
|
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
|
CWE-287
Improper Authentication
|
CVE-2017-7546
|
2024-11-21 12:32 |
2017-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247142
|
7.5 |
HIGH
Network
|
apache
|
tomcat
|
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypa…
|
CWE-22
Path Traversal
|
CVE-2017-7675
|
2024-11-21 12:32 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247143
|
4.3 |
MEDIUM
Network
|
apache
|
tomcat
|
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Orig…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2017-7674
|
2024-11-21 12:32 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247144
|
4.9 |
MEDIUM
Network
|
fortinet
|
fortiweb
|
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.
|
CWE-200 CWE-552
Information Exposure Files or Directories Accessible to External Parties
|
CVE-2017-7737
|
2024-11-21 12:32 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247145
|
10.0 |
CRITICAL
Network
|
selinc
|
sel-3620_firmware sel-3622_firmware
|
An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and, R203, R203-V1, R203-V2 and, R204, R204-V1. The d…
|
NVD-CWE-noinfo
|
CVE-2017-7928
|
2024-11-21 12:32 |
2017-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247146
|
7.5 |
HIGH
Network
|
abb
|
vsn300_firmware vsn300_for_react_firmware
|
An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific unifo…
|
CWE-287
Improper Authentication
|
CVE-2017-7920
|
2024-11-21 12:32 |
2017-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247147
|
6.5 |
MEDIUM
Network
|
abb
|
vsn300_firmware vsn300_for_react_firmware
|
A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web a…
|
CWE-269
Improper Privilege Management
|
CVE-2017-7916
|
2024-11-21 12:32 |
2017-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247148
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that …
|
CWE-362
Race Condition
|
CVE-2017-7533
|
2024-11-21 12:32 |
2017-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247149
|
6.5 |
MEDIUM
Network
|
php
|
php
|
The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A…
|
CWE-200
Information Exposure
|
CVE-2017-7890
|
2024-11-21 12:32 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247150
|
7.8 |
HIGH
Local
|
hashicorp
|
vagrant_vmware_fusion
|
The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the enco…
|
CWE-426
Untrusted Search Path
|
CVE-2017-7642
|
2024-11-21 12:32 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|