|
251841
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira
|
The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16863
|
2024-11-21 12:17 |
2018-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251842
|
5.3 |
MEDIUM
Network
|
atlassian
|
jira
|
The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an env…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-16865
|
2024-11-21 12:17 |
2018-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251843
|
5.5 |
MEDIUM
Local
|
k7computing
|
antivirus internet_security ultimate_security endpoint total_security
|
In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sendi…
|
CWE-20
Improper Input Validation
|
CVE-2017-17429
|
2024-11-21 12:17 |
2018-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251844
|
9.8 |
CRITICAL
Network
|
fiberhome
|
lm53q1_firmware
|
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure …
|
CWE-275
Permission Issues
|
CVE-2017-16887
|
2024-11-21 12:17 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251845
|
8.8 |
HIGH
Network
|
fiberhome
|
lm53q1_firmware
|
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an…
|
CWE-352
Origin Validation Error
|
CVE-2017-16886
|
2024-11-21 12:17 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251846
|
9.8 |
CRITICAL
Network
|
fiberhome
|
lm53q1_firmware
|
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to l…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-16885
|
2024-11-21 12:17 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251847
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira
|
The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16864
|
2024-11-21 12:17 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251848
|
4.3 |
MEDIUM
Network
|
atlassian
|
jira
|
The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.
|
CWE-352
Origin Validation Error
|
CVE-2017-16862
|
2024-11-21 12:17 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251849
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspe…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16878
|
2024-11-21 12:17 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251850
|
8.1 |
HIGH
Network
|
duolingo
|
tinycards
|
The DuoLingo TinyCards application before 1.0 for Android has one use of unencrypted HTTP, which allows remote attackers to spoof content, and consequently achieve remote code execution, via a man-in…
|
CWE-94
Code Injection
|
CVE-2017-16905
|
2024-11-21 12:17 |
2018-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|