|
248991
|
8.8 |
HIGH
Network
|
google debian
|
chrome debian_linux
|
Use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
|
CWE-416
Use After Free
|
CVE-2017-5127
|
2024-11-21 12:27 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248992
|
8.8 |
HIGH
Network
|
google debian
|
chrome debian_linux
|
A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
|
CWE-416
Use After Free
|
CVE-2017-5126
|
2024-11-21 12:27 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248993
|
8.8 |
HIGH
Network
|
google debian
|
chrome debian_linux
|
Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5125
|
2024-11-21 12:27 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248994
|
6.1 |
MEDIUM
Network
|
google debian
|
chrome debian_linux
|
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5124
|
2024-11-21 12:27 |
2018-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248995
|
7.2 |
HIGH
Network
|
moxa
|
softnvr-ia_live_view
|
An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior versions. An uncontrolled search path element (DLL Hijacking) vulnerability has be…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-5170
|
2024-11-21 12:27 |
2018-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248996
|
8.0 |
HIGH
Adjacent
|
cambiumnetworks
|
cnpilot_r190v_firmware cnpilot_e410_firmware cnpilot_r190n_firmware cnpilot_e400_firmware cnpilot_e600_firmware
|
Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typically implemented as randomized per-session token…
|
CWE-352
Origin Validation Error
|
CVE-2017-5263
|
2024-11-21 12:27 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248997
|
8.0 |
HIGH
Adjacent
|
cambiumnetworks
|
cnpilot_r190v_firmware cnpilot_e410_firmware cnpilot_r190n_firmware cnpilot_e400_firmware cnpilot_e600_firmware
|
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference.
|
CWE-200
Information Exposure
|
CVE-2017-5262
|
2024-11-21 12:27 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248998
|
8.8 |
HIGH
Network
|
cambiumnetworks
|
cnpilot_r190v_firmware cnpilot_e410_firmware cnpilot_r190n_firmware cnpilot_e400_firmware cnpilot_e600_firmware
|
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerability, accessible to …
|
CWE-22
Path Traversal
|
CVE-2017-5261
|
2024-11-21 12:27 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248999
|
8.8 |
HIGH
Network
|
cambiumnetworks
|
cnpilot_r190v_firmware cnpilot_e410_firmware cnpilot_r190n_firmware cnpilot_e400_firmware cnpilot_e600_firmware
|
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or-hostname>/adm/sysc…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-5259
|
2024-11-21 12:27 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249000
|
5.4 |
MEDIUM
Network
|
cambiumnetworks
|
epmp_1000_firmware epmp_2000_firmware
|
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a configuration file over SNMP with XSS strings in certain…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5258
|
2024-11-21 12:27 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|