|
252401
|
8.8 |
HIGH
Network
|
otrs debian
|
otrs debian_linux
|
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attack…
|
CWE-94
Code Injection
|
CVE-2017-16664
|
2024-11-21 12:16 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252402
|
9.8 |
CRITICAL
Network
|
openstack debian
|
swauth swift debian_linux
|
An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieve…
|
CWE-287
Improper Authentication
|
CVE-2017-16613
|
2024-11-21 12:16 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252403
|
8.8 |
HIGH
Network
|
busybox debian vmware redlion canonical
|
busybox debian_linux esxi n-tron_702-w_firmware n-tron_702m12-w_firmware ubuntu_linux
|
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and res…
|
CWE-94
Code Injection
|
CVE-2017-16544
|
2024-11-21 12:16 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252404
|
9.8 |
CRITICAL
Network
|
qacctv
|
jooan_a5_ip_camera_firmware
|
On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core system files including those used for authenticatio…
|
CWE-287
Improper Authentication
|
CVE-2017-16566
|
2024-11-21 12:16 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252405
|
7.5 |
HIGH
Network
|
moxa
|
nport_5110_firmware nport_5130_firmware nport_5150_firmware
|
An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 …
|
CWE-74
Injection
|
CVE-2017-16719
|
2024-11-21 12:16 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252406
|
7.5 |
HIGH
Network
|
moxa
|
nport_5110_firmware nport_5130_firmware nport_5150_firmware
|
An Information Exposure issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 V…
|
CWE-200
Information Exposure
|
CVE-2017-16715
|
2024-11-21 12:16 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252407
|
7.8 |
HIGH
Local
|
hashicorp
|
vagrant
|
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and exploit the suid sudo h…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-16777
|
2024-11-21 12:16 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252408
|
4.3 |
MEDIUM
Physics
|
sandisk
|
secureaccess
|
SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being edited when the user…
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2017-16560
|
2024-11-21 12:16 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252409
|
6.5 |
MEDIUM
Network
|
openstack
|
nova
|
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filte…
|
NVD-CWE-noinfo
|
CVE-2017-16239
|
2024-11-21 12:16 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252410
|
5.4 |
MEDIUM
Network
|
octopus
|
octopus_deploy
|
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16801
|
2024-11-21 12:16 |
2017-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|