|
256581
|
9.6 |
CRITICAL
Network
|
avaya
|
ip_office
|
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11309
|
2024-11-21 12:07 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256582
|
7.5 |
HIGH
Network
|
manageengine
|
servicedesk
|
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticat…
|
CWE-22
Path Traversal
|
CVE-2017-11512
|
2024-11-21 12:07 |
2017-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256583
|
7.5 |
HIGH
Network
|
manageengine
|
servicedesk
|
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticat…
|
CWE-200
Information Exposure
|
CVE-2017-11511
|
2024-11-21 12:07 |
2017-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256584
|
7.5 |
HIGH
Network
|
websense
|
triton_ap_email
|
TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory.
|
CWE-20
Improper Input Validation
|
CVE-2017-11177
|
2024-11-21 12:07 |
2017-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256585
|
8.8 |
HIGH
Network
|
tenable
|
securitycenter
|
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker c…
|
CWE-89
SQL Injection
|
CVE-2017-11508
|
2024-11-21 12:07 |
2017-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256586
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the Athdiag procfs entry does not have a proper address sanity check which may potentia…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11067
|
2024-11-21 12:07 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256587
|
5.9 |
MEDIUM
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, as a result of a race condition between two userspace processes that interact with the …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-11063
|
2024-11-21 12:07 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256588
|
7.5 |
HIGH
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during processing of ACA_NL80211_VENDOR_SUBCMD_EXTSCAN_PN…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11064
|
2024-11-21 12:07 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256589
|
7.5 |
HIGH
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, currently attributes are not validated in __wlan_hdd_cfg80211_do_acs which can potentia…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11062
|
2024-11-21 12:07 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256590
|
7.5 |
HIGH
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing cfg80211 vendor sub command QCA_NL80211_VENDOR_SUBCMD_ROAM, a buffer o…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11061
|
2024-11-21 12:07 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|