|
253141
|
8.8 |
HIGH
Adjacent
|
huawei
|
mate_10_firmware mate_10_pro_firmware mate_9_firmware mate_9_pro_firmware
|
The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15311
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253142
|
7.1 |
HIGH
Network
|
huawei
|
ireader
|
Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious f…
|
CWE-22
Path Traversal
|
CVE-2017-15309
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253143
|
8.8 |
HIGH
Network
|
huawei
|
ireader
|
Huawei iReader app before 8.0.2.301 has an input validation vulnerability due to insufficient validation on the URL used for loading network data. An attacker can control app access and load maliciou…
|
CWE-20
Improper Input Validation
|
CVE-2017-15308
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253144
|
2.3 |
LOW
Local
|
huawei
|
honor_8_firmware
|
Huawei Honor 8 smartphone with software versions earlier than FRD-L04C567B389 and earlier than FRD-L14C567B389 have a permission control vulnerability due to improper authorization configuration on s…
|
NVD-CWE-noinfo
|
CVE-2017-15307
|
2024-11-21 12:14 |
2017-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253145
|
5.7 |
MEDIUM
Adjacent
|
symantec
|
messaging_gateway
|
Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stor…
|
CWE-22
Path Traversal
|
CVE-2017-15532
|
2024-11-21 12:14 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253146
|
8.8 |
HIGH
Network
|
zoom
|
zoom
|
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary…
|
CWE-78
OS Command
|
CVE-2017-15049
|
2024-11-21 12:14 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253147
|
8.8 |
HIGH
Network
|
zoom
|
zoom
|
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handle…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15048
|
2024-11-21 12:14 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253148
|
9.1 |
CRITICAL
Network
|
kemptechnologies
|
web_application_firewall
|
The Application Firewall Pack (AFP, aka Web Application Firewall) component on Kemp Load Balancer devices with software before 7.2.40.1 allows a Security Feature Bypass via an HTTP POST request.
|
NVD-CWE-noinfo
|
CVE-2017-15524
|
2024-11-21 12:14 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253149
|
7.8 |
HIGH
Local
|
heketi_project redhat
|
heketi enterprise_linux
|
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi…
|
-
|
CVE-2017-15104
|
2024-11-21 12:14 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253150
|
8.8 |
HIGH
Network
|
heketi_project redhat
|
heketi enterprise_linux
|
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote …
|
-
|
CVE-2017-15103
|
2024-11-21 12:14 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|