|
252781
|
6.5 |
MEDIUM
Network
|
synology
|
router_manager
|
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated users to write arbitrary files via the dest_folder_p…
|
CWE-22
Path Traversal
|
CVE-2017-15895
|
2024-11-21 12:15 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252782
|
6.5 |
MEDIUM
Network
|
synology
|
diskstation_manager
|
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated users to write arbi…
|
CWE-22
Path Traversal
|
CVE-2017-15894
|
2024-11-21 12:15 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252783
|
6.5 |
MEDIUM
Network
|
synology
|
file_station
|
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parame…
|
CWE-22
Path Traversal
|
CVE-2017-15893
|
2024-11-21 12:15 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252784
|
6.5 |
MEDIUM
Network
|
synology
|
calendar
|
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2017-15891
|
2024-11-21 12:15 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252785
|
7.8 |
HIGH
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a craf…
|
CWE-20
Improper Input Validation
|
CVE-2017-15868
|
2024-11-21 12:15 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252786
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overflow can occur while reading firmware logs.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15813
|
2024-11-21 12:15 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252787
|
8.8 |
HIGH
Network
|
synology
|
diskstation_manager
|
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
|
CWE-77
Command Injection
|
CVE-2017-15889
|
2024-11-21 12:15 |
2017-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252788
|
6.2 |
MEDIUM
Local
|
apache netapp oracle
|
struts oncommand_balance weblogic_server jd_edwards_enterpriseone_tools retail_xstore_point_of_service financial_services_market_risk_measurement_and_management webcenter_portal …
|
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
|
CWE-20
Improper Input Validation
|
CVE-2017-15707
|
2024-11-21 12:15 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252789
|
9.8 |
CRITICAL
Network
|
apache
|
qpid_broker-j
|
In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a rem…
|
NVD-CWE-noinfo
|
CVE-2017-15702
|
2024-11-21 12:15 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252790
|
7.5 |
HIGH
Network
|
apache
|
qpid_broker-j
|
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-15701
|
2024-11-21 12:15 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|