|
256051
|
9.8 |
CRITICAL
Network
|
oneplus
|
primary_bootloader
|
The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that partition to disab…
|
NVD-CWE-noinfo
|
CVE-2017-11105
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256052
|
7.5 |
HIGH
Network
|
trendmicro
|
control_manager
|
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.
|
CWE-611
XXE
|
CVE-2017-11390
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256053
|
9.8 |
CRITICAL
Network
|
trendmicro
|
control_manager
|
Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.
|
CWE-22
Path Traversal
|
CVE-2017-11389
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256054
|
8.8 |
HIGH
Network
|
trendmicro
|
control_manager
|
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Forme…
|
CWE-89
SQL Injection
|
CVE-2017-11388
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256055
|
7.5 |
HIGH
Network
|
trendmicro
|
control_manager
|
Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-C…
|
CWE-200
Information Exposure
|
CVE-2017-11387
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256056
|
9.8 |
CRITICAL
Network
|
trendmicro
|
control_manager
|
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZD…
|
CWE-89
SQL Injection
|
CVE-2017-11386
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256057
|
9.8 |
CRITICAL
Network
|
trendmicro
|
control_manager
|
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN…
|
CWE-89
SQL Injection
|
CVE-2017-11385
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256058
|
9.8 |
CRITICAL
Network
|
trendmicro
|
control_manager
|
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN…
|
CWE-89
SQL Injection
|
CVE-2017-11384
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256059
|
9.8 |
CRITICAL
Network
|
trendmicro
|
control_manager
|
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN…
|
CWE-89
SQL Injection
|
CVE-2017-11383
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256060
|
6.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a …
|
CWE-269
Improper Privilege Management
|
CVE-2017-11438
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|