|
257411
|
5.3 |
MEDIUM
Network
|
opendaylight
|
opendaylight
|
StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Ver…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-1000360
|
2024-11-21 12:04 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257412
|
5.3 |
MEDIUM
Network
|
opendaylight
|
opendaylight
|
Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-1000359
|
2024-11-21 12:04 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257413
|
6.5 |
MEDIUM
Network
|
opendaylight
|
opendaylight
|
Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: OpenDaylight 4.0 is af…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-1000358
|
2024-11-21 12:04 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257414
|
7.5 |
HIGH
Network
|
opendaylight
|
opendaylight
|
Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for t…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-1000357
|
2024-11-21 12:04 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257415
|
7.5 |
HIGH
Network
|
wordpress
|
wordpress
|
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows …
|
NVD-CWE-noinfo
|
CVE-2017-1001000
|
2024-11-21 12:04 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257416
|
7.5 |
HIGH
Network
|
ui
|
airos edgemax_firmware
|
Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Protocol in amplification attacks.
|
CWE-20
Improper Input Validation
|
CVE-2017-0938
|
2024-11-21 12:03 |
2019-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257417
|
7.5 |
HIGH
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network reso…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-0929
|
2024-11-21 12:03 |
2018-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257418
|
8.1 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account ta…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2017-0921
|
2024-11-21 12:03 |
2018-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257419
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perfor…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-0919
|
2024-11-21 12:03 |
2018-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257420
|
4.7 |
MEDIUM
Local
|
ubnt
|
ucrm
|
Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. Succ…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-0913
|
2024-11-21 12:03 |
2018-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|