|
247171
|
5.9 |
MEDIUM
Network
|
apache
|
struts
|
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validati…
|
CWE-20
Improper Input Validation
|
CVE-2017-7672
|
2024-11-21 12:32 |
2017-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247172
|
7.5 |
HIGH
Network
|
f5 puppet apple
|
nginx puppet_enterprise xcode
|
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered …
|
-
|
CVE-2017-7529
|
2024-11-21 12:32 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247173
|
6.1 |
MEDIUM
Network
|
apache
|
spark
|
In Apache Spark before 2.2.0, it is possible for an attacker to take advantage of a user's trust in the server to trick them into visiting a link that points to a shared Spark cluster and submits dat…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7678
|
2024-11-21 12:32 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247174
|
7.5 |
HIGH
Network
|
ismartalarm
|
cubeone_firmware
|
iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.
|
CWE-20
Improper Input Validation
|
CVE-2017-7730
|
2024-11-21 12:32 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247175
|
7.5 |
HIGH
Network
|
ismartalarm
|
cubeone_firmware
|
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-7729
|
2024-11-21 12:32 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247176
|
9.8 |
CRITICAL
Network
|
ismartalarm
|
cubeone_firmware
|
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.
|
NVD-CWE-noinfo
|
CVE-2017-7728
|
2024-11-21 12:32 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247177
|
7.5 |
HIGH
Network
|
ismartalarm
|
cubeone_firmware
|
iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-7726
|
2024-11-21 12:32 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247178
|
7.5 |
HIGH
Network
|
apache
|
traffic_control
|
The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DNS port will remain …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-7670
|
2024-11-21 12:32 |
2017-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247179
|
9.8 |
CRITICAL
Network
|
redhat
|
3scale_api_management_platform
|
Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authenticatio…
|
CWE-863
Incorrect Authorization
|
CVE-2017-7512
|
2024-11-21 12:32 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247180
|
7.5 |
HIGH
Network
|
apache
|
solr
|
Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster a…
|
CWE-287
Improper Authentication
|
CVE-2017-7660
|
2024-11-21 12:32 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|