|
247951
|
8.1 |
HIGH
Network
|
lenovo
|
service_framework
|
The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded applications and/or data. This exposes the application to man…
|
CWE-354 CWE-522
Improper Validation of Integrity Check Value Insufficiently Protected Credentials
|
CVE-2017-3760
|
2024-11-21 12:26 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247952
|
8.1 |
HIGH
Network
|
lenovo
|
service_framework
|
The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote…
|
CWE-20
Improper Input Validation
|
CVE-2017-3759
|
2024-11-21 12:26 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247953
|
9.8 |
CRITICAL
Network
|
lenovo
|
service_framework
|
Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.
|
NVD-CWE-noinfo
|
CVE-2017-3758
|
2024-11-21 12:26 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247954
|
8.6 |
HIGH
Network
|
cisco
|
firepower_extensible_operating_system fxos nx-os
|
A vulnerability in the authentication, authorization, and accounting (AAA) implementation of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an unauthenticate…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-3883
|
2024-11-21 12:26 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247955
|
8.8 |
HIGH
Network
|
lenovo
|
xclarity_administrator
|
Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the u…
|
NVD-CWE-noinfo
|
CVE-2017-3770
|
2024-11-21 12:26 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247956
|
6.7 |
MEDIUM
Local
|
lenovo
|
xclarity_administrator
|
An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA versions earlier than 1.3.2.
|
NVD-CWE-noinfo
|
CVE-2017-3763
|
2024-11-21 12:26 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247957
|
5.4 |
MEDIUM
Network
|
vmware
|
vcenter_server
|
VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which …
|
CWE-79
Cross-site Scripting
|
CVE-2017-4926
|
2024-11-21 12:26 |
2017-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247958
|
5.5 |
MEDIUM
Local
|
vmware
|
esxi workstation workstation_pro fusion
|
VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Workstation (12.x before 12.5.3), Fusion (8.x before 8.5.…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-4925
|
2024-11-21 12:26 |
2017-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247959
|
8.8 |
HIGH
Local
|
vmware
|
fusion esxi workstation_pro
|
VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8) contain an out-of-bounds write vulnerability in SVGA device. This issue may a…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-4924
|
2024-11-21 12:26 |
2017-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247960
|
5.9 |
MEDIUM
Network
|
mcafee
|
livesafe
|
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registr…
|
CWE-20
Improper Input Validation
|
CVE-2017-3898
|
2024-11-21 12:26 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|