|
248321
|
7.0 |
HIGH
Local
|
fedoraproject
|
arm_installer
|
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary direc…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2017-7496
|
2024-11-21 12:32 |
2017-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248322
|
7.6 |
HIGH
Network
|
cambium_networks
|
epmp_1000_firmware epmp_elevate_firmware epmp_2000_firmware epmp_1000_hotspot_firmware
|
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to se…
|
CWE-269
Improper Privilege Management
|
CVE-2017-7922
|
2024-11-21 12:32 |
2017-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248323
|
6.8 |
MEDIUM
Network
|
cambium_networks
|
epmp_1000_firmware epmp_elevate_firmware epmp_2000_firmware epmp_1000_hotspot_firmware
|
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able to remotely trigger device configuration backups u…
|
CWE-269
Improper Privilege Management
|
CVE-2017-7918
|
2024-11-21 12:32 |
2017-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248324
|
9.8 |
CRITICAL
Network
|
apache
|
http_server
|
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7679
|
2024-11-21 12:32 |
2017-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248325
|
7.5 |
HIGH
Network
|
apache netapp redhat debian oracle apple
|
http_server storagegrid clustered_data_ontap oncommand_unified_manager enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_t…
|
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-7668
|
2024-11-21 12:32 |
2017-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248326
|
7.5 |
HIGH
Network
|
gnu
|
gnutls
|
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server appli…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-7507
|
2024-11-21 12:32 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248327
|
8.4 |
HIGH
Local
|
apcupsd
|
apc_ups_daemon
|
In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to run arbitrary code with elevated privileges by rep…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-7884
|
2024-11-21 12:32 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248328
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 bu…
|
CWE-77
Command Injection
|
CVE-2017-7876
|
2024-11-21 12:32 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248329
|
7.5 |
HIGH
Network
|
qnap
|
qts
|
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2017-7629
|
2024-11-21 12:32 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248330
|
8.6 |
HIGH
Network
|
rockwellautomation
|
panelview_plus_6_700-1500_firmware
|
A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012, 6.10-20140122, 7.00-20121012, 7.00-20130108, 7.0…
|
CWE-862
Missing Authorization
|
CVE-2017-7914
|
2024-11-21 12:32 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|