|
252181
|
9.9 |
CRITICAL
Network
|
insteon
|
hub_firmware
|
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012. At 0x9d01bb1c the value for the uri key is copied using strcpy to the …
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-16339
|
2024-11-21 12:16 |
2018-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252182
|
9.9 |
CRITICAL
Network
|
insteon
|
hub_firmware
|
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012. At 0x9d01bad0 the value for the host key is copied using strcpy to the…
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-16338
|
2024-11-21 12:16 |
2018-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252183
|
4.8 |
MEDIUM
Network
|
crestron
|
airmedia_am-100_firmware airmedia_am-101_firmware
|
Cross-site scripting (XSS) vulnerability in Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote attackers to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16710
|
2024-11-21 12:16 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252184
|
7.2 |
HIGH
Network
|
crestron
|
airmedia_am-100_firmware airmedia_am-101_firmware
|
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote authenticated administrators to execute arbitrary code via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2017-16709
|
2024-11-21 12:16 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252185
|
8.8 |
HIGH
Network
|
synology
|
universal_search
|
Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass permission checks for directories in POSIX mode.
|
CWE-863
Incorrect Authorization
|
CVE-2017-16773
|
2024-11-21 12:16 |
2018-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252186
|
9.1 |
CRITICAL
Network
|
beckhoff
|
twincat
|
Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-16726
|
2024-11-21 12:16 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252187
|
5.9 |
MEDIUM
Network
|
beckhoff
|
twincat
|
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via A…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2017-16718
|
2024-11-21 12:16 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252188
|
6.1 |
MEDIUM
Network
|
sensiolabs debian
|
symfony debian_linux
|
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler t…
|
CWE-601
Open Redirect
|
CVE-2017-16652
|
2024-11-21 12:16 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252189
|
9.8 |
CRITICAL
Network
|
static-eval_project
|
static-eval
|
The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing ar…
|
CWE-20
Improper Input Validation
|
CVE-2017-16226
|
2024-11-21 12:16 |
2018-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252190
|
7.5 |
HIGH
Network
|
aegir_project
|
aegir
|
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (that performed a aegir-release) GitHub token.
|
CWE-200
Information Exposure
|
CVE-2017-16225
|
2024-11-21 12:16 |
2018-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|