|
249231
|
8.8 |
HIGH
Adjacent
|
iodata
|
wn-ax1167gr_firmware
|
WN-AX1167GR firmware version 3.00 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-2280
|
2024-11-21 12:23 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249232
|
7.8 |
HIGH
Local
|
kiri
|
tween
|
Untrusted search path vulnerability in Tween Ver1.6.6.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2017-2279
|
2024-11-21 12:23 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249233
|
5.9 |
MEDIUM
Network
|
iid
|
rbb_speed_test
|
The RBB SPEED TEST App for Android version 2.0.3 and earlier, RBB SPEED TEST App for iOS version 2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle …
|
CWE-295
Improper Certificate Validation
|
CVE-2017-2278
|
2024-11-21 12:23 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249234
|
7.8 |
HIGH
Local
|
sony
|
nfc_port_firmware pc\/sc_activator_for_type_b sfcard_viewer_2 nfc_net_installer
|
Untrusted search path vulnerability in NFC Port Software Version 5.5.0.6 and earlier (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S), NFC Port Software Version 5.3.6.7 and earlier (for R…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-2286
|
2024-11-21 12:23 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249235
|
9.1 |
CRITICAL
Network
|
sony
|
wg-c10_firmware
|
WG-C10 v3.0.79 and earlier allows an attacker to bypass access restrictions to obtain or alter information stored in the external storage connected to the product via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2017-2277
|
2024-11-21 12:23 |
2017-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249236
|
7.2 |
HIGH
Network
|
sony
|
wg-c10_firmware
|
Buffer overflow in WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-2276
|
2024-11-21 12:23 |
2017-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249237
|
7.2 |
HIGH
Network
|
sony
|
wg-c10_firmware
|
WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2017-2275
|
2024-11-21 12:23 |
2017-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249238
|
6.1 |
MEDIUM
Network
|
buffalo
|
wmr-433_firmware wmr-433w_firmware
|
Cross-site scripting vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vect…
|
CWE-79
Cross-site Scripting
|
CVE-2017-2274
|
2024-11-21 12:23 |
2017-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249239
|
8.8 |
HIGH
Network
|
buffalo
|
wmr-433_firmware wmr-433w_firmware
|
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators…
|
CWE-352
Origin Validation Error
|
CVE-2017-2273
|
2024-11-21 12:23 |
2017-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249240
|
6.5 |
MEDIUM
Network
|
apple
|
iphone_os
|
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
|
CWE-20
Improper Input Validation
|
CVE-2017-2517
|
2024-11-21 12:23 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|