|
247551
|
8.8 |
HIGH
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative inte…
|
CWE-352
Origin Validation Error
|
CVE-2017-8836
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247552
|
9.8 |
CRITICAL
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth coo…
|
CWE-89
SQL Injection
|
CVE-2017-8835
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247553
|
4.3 |
MEDIUM
Network
|
elastic
|
x-pack
|
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data…
|
CWE-200
Information Exposure
|
CVE-2017-8441
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247554
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions …
|
CWE-79
Cross-site Scripting
|
CVE-2017-8440
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247555
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8439
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247556
|
8.8 |
HIGH
Network
|
elastic
|
x-pack
|
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into the specified user specified in a run_as request. …
|
CWE-269
Improper Privilege Management
|
CVE-2017-8438
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247557
|
6.5 |
MEDIUM
Network
|
libming
|
libming
|
The readString function in util/read.c and util/old/read.c in libming 0.4.8 allows remote attackers to cause a denial of service via a large file that is mishandled by listswf, listaction, etc. This …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-8782
|
2024-11-21 12:34 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247558
|
5.5 |
MEDIUM
Local
|
microsoft
|
forefront_security malware_protection_engine windows_defender
|
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and…
|
CWE-119 CWE-369 CWE-476 CWE-674
Incorrect Access of Indexable Resource ('Range Error') Divide By Zero NULL Pointer Dereference Uncontrolled Recursion
|
CVE-2017-8542
|
2024-11-21 12:34 |
2017-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247559
|
7.8 |
HIGH
Local
|
microsoft
|
forefront_security malware_protection_engine windows_defender
|
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8541
|
2024-11-21 12:34 |
2017-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247560
|
5.5 |
MEDIUM
Local
|
microsoft
|
forefront_security malware_protection_engine windows_defender
|
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and…
|
CWE-119 CWE-369 CWE-476 CWE-674
Incorrect Access of Indexable Resource ('Range Error') Divide By Zero NULL Pointer Dereference Uncontrolled Recursion
|
CVE-2017-8539
|
2024-11-21 12:34 |
2017-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|