|
247751
|
9.8 |
CRITICAL
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus firefox fir…
|
A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < …
|
CWE-416
Use After Free
|
CVE-2017-7749
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247752
|
8.8 |
HIGH
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus firefox fir…
|
A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash bu…
|
CWE-416
Use After Free
|
CVE-2017-7752
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247753
|
9.8 |
CRITICAL
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus firefox fir…
|
A use-after-free vulnerability during video control operations when a "<track>" element holds a reference to an older window if that window has been replaced in the DOM. This results in a potentially…
|
CWE-416
Use After Free
|
CVE-2017-7750
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247754
|
9.8 |
CRITICAL
Network
|
abb
|
ip_gateway_firmware
|
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized access.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-7933
|
2024-11-21 12:32 |
2018-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247755
|
9.8 |
CRITICAL
Network
|
abb
|
ip_gateway_firmware
|
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the configuration files and application pages without au…
|
CWE-287
Improper Authentication
|
CVE-2017-7931
|
2024-11-21 12:32 |
2018-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247756
|
8.8 |
HIGH
Network
|
abb
|
ip_gateway_firmware
|
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating tha…
|
CWE-352
Origin Validation Error
|
CVE-2017-7906
|
2024-11-21 12:32 |
2018-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247757
|
5.3 |
MEDIUM
Network
|
qnap
|
nas_proxy_server
|
QNAP NAS application Proxy Server through version 1.2.0 does not authenticate requests properly. Successful exploitation can lead to change of the settings of Proxy Server.
|
CWE-287
Improper Authentication
|
CVE-2017-7639
|
2024-11-21 12:32 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247758
|
9.8 |
CRITICAL
Network
|
qnap
|
nas_proxy_server
|
QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges.
|
CWE-78
OS Command
|
CVE-2017-7637
|
2024-11-21 12:32 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247759
|
6.1 |
MEDIUM
Network
|
qnap
|
nas_proxy_server
|
Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7636
|
2024-11-21 12:32 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247760
|
8.8 |
HIGH
Network
|
qnap
|
nas_proxy_server
|
QNAP NAS application Proxy Server through version 1.2.0 does not utilize CSRF protections.
|
CWE-352
Origin Validation Error
|
CVE-2017-7635
|
2024-11-21 12:32 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|