|
255291
|
5.9 |
MEDIUM
Network
|
cisco
|
ios ios_xe
|
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized ac…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-12228
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255292
|
8.8 |
HIGH
Network
|
cisco
|
ios_xe
|
A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, and Cisco Ne…
|
CWE-20
Improper Input Validation
|
CVE-2017-12226
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255293
|
6.5 |
MEDIUM
Adjacent
|
cisco
|
ios_xe
|
A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch and result in a denial of service (DoS) condition…
|
CWE-20
Improper Input Validation
|
CVE-2017-12222
|
2024-11-21 12:09 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255294
|
9.8 |
CRITICAL
Network
|
apache
|
commons_jelly
|
During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser insta…
|
CWE-611
XXE
|
CVE-2017-12621
|
2024-11-21 12:09 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255295
|
6.7 |
MEDIUM
Local
|
cisco
|
unified_computing_system
|
A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access. The vulnerability is due to insufficient input validation of commands enter…
|
CWE-20
Improper Input Validation
|
CVE-2017-12255
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255296
|
8.8 |
HIGH
Network
|
cisco
|
unified_intelligence_center
|
A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery …
|
CWE-352
Origin Validation Error
|
CVE-2017-12253
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255297
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_intelligence_center
|
A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack. T…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12254
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255298
|
7.8 |
HIGH
Local
|
cisco
|
findit_network_discovery_utility
|
A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to device availabil…
|
CWE-426
Untrusted Search Path
|
CVE-2017-12252
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255299
|
5.3 |
MEDIUM
Network
|
cisco
|
wide_area_application_services
|
A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an HTTP Application Optimization (AO) related proces…
|
CWE-20
Improper Input Validation
|
CVE-2017-12250
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255300
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_intelligence_center
|
A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user o…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12248
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|