|
252521
|
7.5 |
HIGH
Network
|
devada
|
dzone_answerhub
|
An XML External Entity Injection vulnerability exists in Dzone AnswerHub.
|
CWE-611
XXE
|
CVE-2017-15725
|
2024-11-21 12:15 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252522
|
6.5 |
MEDIUM
Network
|
apache
|
geode
|
When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could m…
|
CWE-88
Argument Injection
|
CVE-2017-15694
|
2024-11-21 12:15 |
2019-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252523
|
5.5 |
MEDIUM
Local
|
qualcomm
|
sd_410_firmware sd_412_firmware sd_425_firmware sd_427_firmware sd_430_firmware sd_435_firmware sd_450_firmware sd_615_firmware sd_616_firmware sd_415_firmware sd_625_fi…
|
When HOST sends a Special command ID packet, Controller triggers a RAM Dump and FW reset in Snapdragon Mobile in version SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, S…
|
NVD-CWE-noinfo
|
CVE-2017-15841
|
2024-11-21 12:15 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252524
|
8.8 |
HIGH
Network
|
apache
|
airflow
|
In Apache Airflow 1.8.2 and earlier, an authenticated user can execute code remotely on the Airflow webserver by creating a special object.
|
CWE-20
Improper Input Validation
|
CVE-2017-15720
|
2024-11-21 12:15 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252525
|
6.5 |
MEDIUM
Adjacent
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While processing the RIC Data Descriptor IE in an artificially crafted 802.11 frame with IE …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-15835
|
2024-11-21 12:15 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252526
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the function for writing device values into flash, uninitialized memory ca…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-15844
|
2024-11-21 12:15 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252527
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while accessing the keystore in LK, an integer overflow vulnerability exists which may pote…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-15828
|
2024-11-21 12:15 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252528
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a gpt update, an out of bounds memory access may potentially occur.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-15825
|
2024-11-21 12:15 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252529
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while loading a user application in qseecom, an integer overflow could potentially occur if…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-15818
|
2024-11-21 12:15 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252530
|
5.3 |
MEDIUM
Network
|
apache redhat debian canonical
|
spamassassin enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux ubuntu_linux enterprise_linux_eus
|
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorre…
|
CWE-20
Improper Input Validation
|
CVE-2017-15705
|
2024-11-21 12:15 |
2018-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|