|
251871
|
7.5 |
HIGH
Network
|
flexense
|
syncbreeze
|
The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests in the Host header …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17088
|
2024-11-21 12:17 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251872
|
9.8 |
CRITICAL
Network
|
zivif
|
pr115-204-p-rs_firmware
|
Zivif PR115-204-P-RS V2.3.4.2103 web cameras contain a hard-coded cat1029 password for the root user. The SONIX operating system's setup renders this password unchangeable and it can be used to acces…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-17107
|
2024-11-21 12:17 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251873
|
9.8 |
CRITICAL
Network
|
zivif
|
pr115-204-p-rs_firmware
|
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerabil…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-17106
|
2024-11-21 12:17 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251874
|
9.8 |
CRITICAL
Network
|
zivif
|
pr115-204-p-rs_firmware
|
Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the w…
|
CWE-78
OS Command
|
CVE-2017-17105
|
2024-11-21 12:17 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251875
|
9.8 |
CRITICAL
Network
|
accesspressthemes
|
anonymous_post_pro
|
An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settings for allowed file …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-16949
|
2024-11-21 12:17 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251876
|
7.8 |
HIGH
Local
|
gnu redhat
|
glibc enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to g…
|
CWE-426
Untrusted Search Path
|
CVE-2017-16997
|
2024-11-21 12:17 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251877
|
6.1 |
MEDIUM
Network
|
urbackup
|
urbackup_server
|
Cross - site scripting (XSS) vulnerability in UrBackup Server before 2.1.20 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16950
|
2024-11-21 12:17 |
2017-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251878
|
8.8 |
HIGH
Network
|
ruby-lang debian redhat
|
ruby debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_server_tus
|
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument star…
|
CWE-78
OS Command
|
CVE-2017-17405
|
2024-11-21 12:17 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251879
|
5.9 |
MEDIUM
Network
|
radware
|
alteon_firmware
|
Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext attack ("Bleichenbacher attack"). This allows an attacker to decrypt observed …
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2017-17427
|
2024-11-21 12:17 |
2017-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251880
|
5.9 |
MEDIUM
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware
|
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 might allow remote …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2017-17382
|
2024-11-21 12:17 |
2017-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|