|
253021
|
9.8 |
CRITICAL
Network
|
bacula
|
bacula-web
|
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on th…
|
CWE-89
SQL Injection
|
CVE-2017-15367
|
2024-11-21 12:14 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253022
|
7.2 |
HIGH
Network
|
netapp
|
snapcenter_server
|
Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File Services. All users are urged to move to version 3.…
|
CWE-287
Improper Authentication
|
CVE-2017-15519
|
2024-11-21 12:14 |
2018-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253023
|
5.9 |
MEDIUM
Network
|
dovecot debian canonical
|
dovecot debian_linux ubuntu_linux
|
A denial of service flaw was found in dovecot before 2.2.34. An attacker able to generate random SNI server names could exploit TLS SNI configuration lookups, leading to excessive memory usage and th…
|
NVD-CWE-noinfo
|
CVE-2017-15130
|
2024-11-21 12:14 |
2018-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253024
|
7.5 |
HIGH
Network
|
fedoraproject redhat
|
389_directory_server enterprise_linux_desktop enterprise_linux enterprise_linux_workstation enterprise_linux_server
|
A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated atta…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15134
|
2024-11-21 12:14 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253025
|
2.7 |
LOW
Network
|
redhat
|
satellite
|
When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered system the previously registered system will…
|
NVD-CWE-noinfo
|
CVE-2017-15136
|
2024-11-21 12:14 |
2018-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253026
|
7.8 |
HIGH
Local
|
netapp
|
service_level_manager oncommand_api_services
|
All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account password. All users are urged to move to a fixed version. S…
|
CWE-200
Information Exposure
|
CVE-2017-15518
|
2024-11-21 12:14 |
2018-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253027
|
8.8 |
HIGH
Network
|
infinispan
|
infinispan
|
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-15089
|
2024-11-21 12:14 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253028
|
6.8 |
MEDIUM
Physics
|
huawei
|
honor_v9_play_firmware
|
The 'Find Phone' function in Huawei Honor V9 play smart phones with versions earlier than Jimmy-AL00AC00B135 has an authentication bypass vulnerability. Due to improper authentication realization in …
|
CWE-287
Improper Authentication
|
CVE-2017-15351
|
2024-11-21 12:14 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253029
|
5.5 |
MEDIUM
Local
|
huawei
|
mate_9_pro_firmware
|
Huawei Mate 9 Pro mobile phones with software of versions earlier than LON-AL00BC00B235 have a use after free (UAF) vulnerability. An attacker tricks a user into installing a malicious application, a…
|
CWE-416
Use After Free
|
CVE-2017-15347
|
2024-11-21 12:14 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253030
|
5.3 |
MEDIUM
Adjacent
|
huawei
|
lon-l29d_firmware
|
Huawei Smartphones with software LON-L29DC721B186 have a denial of service vulnerability. An attacker could make an loop exit condition that cannot be reached by sending the crafted 3GPP message. Suc…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-15345
|
2024-11-21 12:14 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|