|
247641
|
8.8 |
HIGH
Network
|
icoutils_project debian redhat
|
icoutils debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_serve…
|
Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of servic…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5208
|
2024-11-21 12:27 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247642
|
8.8 |
HIGH
Network
|
microfocus
|
enterprise_server_monitor_and_control enterprise_developer enterprise_server directory_server
|
A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 U…
|
CWE-352
Origin Validation Error
|
CVE-2017-5187
|
2024-11-21 12:27 |
2017-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247643
|
5.4 |
MEDIUM
Network
|
biscom
|
secure_file_transfer
|
Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field. An authenticated user with permissions to upload or send files can populate this field with a filename that c…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5247
|
2024-11-21 12:27 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247644
|
4.3 |
MEDIUM
Network
|
biscom
|
secure_file_transfer
|
Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in doub…
|
CWE-74
Injection
|
CVE-2017-5246
|
2024-11-21 12:27 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247645
|
5.9 |
MEDIUM
Network
|
bestpractical
|
request_tracker
|
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain…
|
NVD-CWE-noinfo
|
CVE-2017-5361
|
2024-11-21 12:27 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247646
|
6.5 |
MEDIUM
Network
|
tibco
|
jasperreports_library_community_edition jasperreports_library_for_activematrix_bpm jasperreports_professional jasperreports_server jasperreports_server_community_edition jasperreports_…
|
JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affec…
|
CWE-200
Information Exposure
|
CVE-2017-5529
|
2024-11-21 12:27 |
2017-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247647
|
8.8 |
HIGH
Network
|
tibco
|
jasperreports_server jaspersoft jaspersoft_reporting_and_analytics
|
Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of t…
|
CWE-352
Origin Validation Error
|
CVE-2017-5528
|
2024-11-21 12:27 |
2017-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247648
|
5.4 |
MEDIUM
Network
|
biscom
|
secure_file_transfer
|
Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in the "Name" and "Description" fields of a Workspace, as well…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5241
|
2024-11-21 12:27 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247649
|
3.5 |
LOW
Network
|
rapid7
|
metasploit
|
Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have been allowed, as the stop/stop_all routes change the state of t…
|
CWE-352
Origin Validation Error
|
CVE-2017-5244
|
2024-11-21 12:27 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247650
|
8.5 |
HIGH
Network
|
rapid7
|
nexpose
|
The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2017-5243
|
2024-11-21 12:27 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|