|
249341
|
7.8 |
HIGH
Local
|
realtek
|
audio_driver_firmware
|
A local privilege escalation vulnerability was identified in the Realtek audio driver versions prior to 6.0.1.8224 in some Lenovo ThinkPad products. An attacker with local privileges could execute co…
|
NVD-CWE-noinfo
|
CVE-2017-3767
|
2024-11-21 12:26 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249342
|
6.5 |
MEDIUM
Network
|
openssl
|
openssl
|
There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RS…
|
CWE-200
Information Exposure
|
CVE-2017-3736
|
2024-11-21 12:26 |
2017-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249343
|
7.5 |
HIGH
Network
|
mcafee
|
network_data_loss_prevention
|
Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the response body, potentially causing the response body …
|
CWE-200
Information Exposure
|
CVE-2017-3935
|
2024-11-21 12:26 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249344
|
5.9 |
MEDIUM
Network
|
mcafee
|
network_data_loss_prevention
|
Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data…
|
CWE-200
Information Exposure
|
CVE-2017-3934
|
2024-11-21 12:26 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249345
|
5.4 |
MEDIUM
Network
|
mcafee
|
network_data_loss_prevention
|
Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via a cross site request fo…
|
CWE-79
Cross-site Scripting
|
CVE-2017-3933
|
2024-11-21 12:26 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249346
|
6.5 |
MEDIUM
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to perform domain spoofing via I…
|
CWE-20
Improper Input Validation
|
CVE-2017-5076
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249347
|
4.3 |
MEDIUM
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value …
|
CWE-200
Information Exposure
|
CVE-2017-5075
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249348
|
8.0 |
HIGH
Adjacent
|
google
|
chrome
|
A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth.
|
CWE-416
Use After Free
|
CVE-2017-5074
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249349
|
8.8 |
HIGH
Network
|
google redhat
|
chrome enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Use after free in print preview in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory…
|
CWE-416
Use After Free
|
CVE-2017-5073
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249350
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with RTL characters via a crafted URL page.
|
CWE-20
Improper Input Validation
|
CVE-2017-5072
|
2024-11-21 12:26 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|