|
249551
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2017-6360
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249552
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2017-6359
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249553
|
7.8 |
HIGH
Local
|
apng_disassembler_project
|
apng_disassembler
|
Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6191
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249554
|
6.7 |
MEDIUM
Local
|
avira
|
internet_security_suite free_security_suite total_security_suite optimization_suite
|
Code injection vulnerability in Avira Total Security Suite 15.0 (and earlier), Optimization Suite 15.0 (and earlier), Internet Security Suite 15.0 (and earlier), and Free Security Suite 15.0 (and ear…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-6417
|
2024-11-21 12:29 |
2017-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249555
|
6.7 |
MEDIUM
Local
|
bitdefender
|
internet_security total_security antivirus_plus
|
Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-pro…
|
CWE-94
Code Injection
|
CVE-2017-6186
|
2024-11-21 12:29 |
2017-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249556
|
5.3 |
MEDIUM
Network
|
paloaltonetworks
|
terminal_services_agent
|
Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-6356
|
2024-11-21 12:29 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249557
|
7.5 |
HIGH
Network
|
opensuse sane-backends_project
|
leap sane-backends
|
saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.
|
CWE-200
Information Exposure
|
CVE-2017-6318
|
2024-11-21 12:29 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249558
|
7.8 |
HIGH
Local
|
usbpcap_project
|
usbpcap
|
The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6178
|
2024-11-21 12:29 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249559
|
7.5 |
HIGH
Network
|
qemu
|
qemu
|
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of se…
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-6058
|
2024-11-21 12:29 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249560
|
5.3 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network an…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-6370
|
2024-11-21 12:29 |
2017-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|