|
248211
|
7.5 |
HIGH
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an obj…
|
CWE-200
Information Exposure
|
CVE-2017-5378
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248212
|
9.8 |
CRITICAL
Network
|
mozilla debian redhat
|
firefox thunderbird firefox_esr debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be explo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5373
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248213
|
7.8 |
HIGH
Local
|
advantech
|
webaccess
|
Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search path resulting in execution of arbitrary code.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-5175
|
2024-11-21 12:27 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248214
|
5.4 |
MEDIUM
Network
|
tibco
|
datasynapse_gridserver_manager
|
The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities which may allow an authenticated user to perform cross-si…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5536
|
2024-11-21 12:27 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248215
|
6.8 |
MEDIUM
Adjacent
|
tibco
|
datasynapse_gridserver_manager
|
The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager contain vulnerabilities related to both the improper use of encr…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-5535
|
2024-11-21 12:27 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248216
|
7.5 |
HIGH
Network
|
netiq
|
imanager
|
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Senti…
|
CWE-287
Improper Authentication
|
CVE-2017-5189
|
2024-11-21 12:27 |
2018-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248217
|
7.5 |
HIGH
Network
|
opensuse
|
open_build_service
|
The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside of the package source directory during build, allowing leakage of private inform…
|
CWE-200 CWE-59
Information Exposure Link Following
|
CVE-2017-5188
|
2024-11-21 12:27 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248218
|
8.1 |
HIGH
Network
|
insteon
|
insteon_hub_firmware
|
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-5251
|
2024-11-21 12:27 |
2018-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248219
|
9.8 |
CRITICAL
Network
|
insteon
|
insteon_for_hub
|
In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
|
CWE-312 CWE-922
Cleartext Storage of Sensitive Information Insecure Storage of Sensitive Information
|
CVE-2017-5250
|
2024-11-21 12:27 |
2018-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248220
|
9.8 |
CRITICAL
Network
|
wink
|
wink
|
In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
|
CWE-312 CWE-922
Cleartext Storage of Sensitive Information Insecure Storage of Sensitive Information
|
CVE-2017-5249
|
2024-11-21 12:27 |
2018-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|