|
251301
|
5.4 |
MEDIUM
Network
|
bose
|
soundtouch
|
Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17749
|
2024-11-21 12:18 |
2018-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251302
|
9.8 |
CRITICAL
Network
|
kentico
|
kentico_cms
|
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashb…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2017-17736
|
2024-11-21 12:18 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251303
|
6.7 |
MEDIUM
Local
|
ucopia
|
wireless_appliance_firmware
|
Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5.1.x before 5.1.11 allows authenticated remote att…
|
CWE-287
Improper Authentication
|
CVE-2017-17743
|
2024-11-21 12:18 |
2018-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251304
|
7.5 |
HIGH
Network
|
ncr
|
s1_dispenser_controller_firmware
|
Memory write mechanism in NCR S1 Dispenser controller before firmware version 0x0156 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions wit…
|
CWE-863
Incorrect Authorization
|
CVE-2017-17668
|
2024-11-21 12:18 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251305
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware sd_210_firmware sd_212_firmware sd_412_firmware sd_410_firmware sd_425_firmware sd_430_firmware sd_616_firmware sd_615…
|
In Snapdragon Automobile, Snapdragon Wearable and Snapdragon Mobile MDM9206,MDM9607,MDM9650,SD 210/SD 212/SD 205,SD 400,SD 410/12,SD 425,SD 430,SD 450,SD 600,SD 602A,SD 615/16/SD 415,SD 617,SD 625,SD…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17773
|
2024-11-21 12:18 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251306
|
4.8 |
MEDIUM
Network
|
pega
|
pega_platform
|
An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and 7.2.2. A user with developer credentials can insert malicious code (up to 64 c…
|
CWE-79
Cross-site Scripting
|
CVE-2017-17478
|
2024-11-21 12:18 |
2018-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251307
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the IL client may free a buffer OMX Video Encoder Component and then subsequently access the already freed buffer.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17767
|
2024-11-21 12:18 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251308
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in wma_get_ll_stats_ext_buf() and are used to allocat…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-17765
|
2024-11-21 12:18 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251309
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the num_failure_info value from firmware is not properly validated in wma_rx_aggr_failure_event_handler() so that an in…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-17764
|
2024-11-21 12:18 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251310
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
In Exiv2 0.26, there is an integer overflow leading to a heap-based buffer over-read in the Exiv2::getULong function in types.cpp. Remote attackers can exploit the vulnerability to cause a denial of …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-17725
|
2024-11-21 12:18 |
2018-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|