|
256061
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read reposi…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-11437
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256062
|
6.5 |
MEDIUM
Network
|
pega
|
pega_platform
|
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by lever…
|
CWE-200
Information Exposure
|
CVE-2017-11356
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256063
|
6.1 |
MEDIUM
Network
|
pega
|
pega_platform
|
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) …
|
CWE-79
Cross-site Scripting
|
CVE-2017-11355
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256064
|
4.4 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11334
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256065
|
9.8 |
CRITICAL
Network
|
sol-connect
|
sol.connect_iset-mpp_meter_firmware
|
SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a login action.
|
CWE-89
SQL Injection
|
CVE-2017-11494
|
2024-11-21 12:07 |
2017-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256066
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-11364
|
2024-11-21 12:07 |
2017-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256067
|
9.8 |
CRITICAL
Network
|
trendmicro
|
deep_discovery_director
|
A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.
|
CWE-78
OS Command
|
CVE-2017-11381
|
2024-11-21 12:07 |
2017-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256068
|
9.8 |
CRITICAL
Network
|
trendmicro
|
deep_discovery_director
|
Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Di…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-11380
|
2024-11-21 12:07 |
2017-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256069
|
7.5 |
HIGH
Network
|
trendmicro
|
deep_discovery_director
|
Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2017-11379
|
2024-11-21 12:07 |
2017-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256070
|
6.5 |
MEDIUM
Network
|
stashcat
|
heinekingmedia
|
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. It uses RSA to exchange a secret for symmetric encryption of mes…
|
NVD-CWE-noinfo
|
CVE-2017-11136
|
2024-11-21 12:07 |
2017-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|