|
251281
|
7.5 |
HIGH
Network
|
episerver
|
episerver
|
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.
|
CWE-611
XXE
|
CVE-2017-17762
|
2024-11-21 12:18 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251282
|
4.3 |
MEDIUM
Network
|
pleasantsolutions
|
pleasant_password_server
|
Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other users in Pleasant Password Server before 7.8.3.
|
CWE-863
Incorrect Authorization
|
CVE-2017-17708
|
2024-11-21 12:18 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251283
|
8.1 |
HIGH
Network
|
pleasantsolutions
|
pleasant_password_server
|
Due to missing authorization checks, any authenticated user is able to list, upload, or delete attachments to password safe entries in Pleasant Password Server before 7.8.3. To perform those actions …
|
CWE-862
Missing Authorization
|
CVE-2017-17707
|
2024-11-21 12:18 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251284
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortianalyzer_firmware fortimanager_firmware
|
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through …
|
CWE-79
Cross-site Scripting
|
CVE-2017-17541
|
2024-11-21 12:18 |
2018-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251285
|
5.9 |
MEDIUM
Network
|
microsoft horde google 9folders flipdogsolutions r2mail2 apple bloop freron kde gnome mozilla ibm emclient postbox-inc ritlabs
|
outlook horde_imp gmail nine maildroid r2mail2 mail airmail mailmate kmail trojita evolution thunderbird notes emclient postbox the_bat
|
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
|
NVD-CWE-noinfo
|
CVE-2017-17689
|
2024-11-21 12:18 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251286
|
5.9 |
MEDIUM
Network
|
microsoft horde flipdogsolutions r2mail2 apple bloop freron mozilla emclient postbox-inc roundcube
|
outlook horde_imp maildroid r2mail2 mail airmail mailmate thunderbird emclient postbox webmail
|
The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a probl…
|
NVD-CWE-noinfo
|
CVE-2017-17688
|
2024-11-21 12:18 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251287
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortiwlc
|
The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-17540
|
2024-11-21 12:18 |
2018-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251288
|
9.8 |
CRITICAL
Network
|
fortinet
|
fortiwlc
|
The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shell.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-17539
|
2024-11-21 12:18 |
2018-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251289
|
7.5 |
HIGH
Network
|
fortinet
|
forticlient forticlient_sslvpn_client
|
Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Clie…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-17543
|
2024-11-21 12:18 |
2018-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251290
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf foxit_reader
|
In Foxit Reader before 9.1 and Foxit PhantomPDF before 9.1, a flaw exists within the parsing of the BITMAPINFOHEADER record in BMP files. The issue results from the lack of proper validation of the b…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17557
|
2024-11-21 12:18 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|