|
248231
|
9.8 |
CRITICAL
Network
|
themidnightcoders
|
weborb_for_java
|
The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externalizable rather than the AMF3 specification's recommen…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3207
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248232
|
9.8 |
CRITICAL
Network
|
exadel
|
flamingo
|
The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If t…
|
CWE-611
XXE
|
CVE-2017-3206
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248233
|
8.1 |
HIGH
Network
|
pivotal
|
spring-flex
|
The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExt…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3203
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248234
|
8.1 |
HIGH
Network
|
exadel
|
flamingo_amf-serializer
|
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class instances from java.io.Externalizable rather than the AMF3 specification's recomme…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3201
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248235
|
8.1 |
HIGH
Network
|
graniteds
|
graniteds
|
The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExte…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3199
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248236
|
9.8 |
CRITICAL
Network
|
exadel
|
flamingo
|
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes via their public parameter-less constructor and su…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3202
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248237
|
8.1 |
HIGH
Network
|
graniteds
|
graniteds
|
The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitr…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3200
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248238
|
7.8 |
HIGH
Local
|
rawether_project
|
rawether
|
PCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory outside of its typical bounds on the driver's receipt of networ…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-3196
|
2024-11-21 12:25 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248239
|
9.8 |
CRITICAL
Network
|
commvault
|
edge
|
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code executio…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-3195
|
2024-11-21 12:25 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248240
|
8.1 |
HIGH
Network
|
pandora
|
pandora
|
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.
|
CWE-200
Information Exposure
|
CVE-2017-3194
|
2024-11-21 12:25 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|