|
250501
|
9.8 |
CRITICAL
Network
|
mcafee
|
epolicy_orchestrator
|
OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run arbitrary OS commands with limited privileges via n…
|
CWE-78
OS Command
|
CVE-2017-3936
|
2024-11-21 12:26 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250502
|
9.8 |
CRITICAL
Network
|
mcafee
|
mcafee_threat_intelligence_exchange
|
Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code t…
|
CWE-94
Code Injection
|
CVE-2017-3907
|
2024-11-21 12:26 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250503
|
9.1 |
CRITICAL
Network
|
mcafee
|
network_security_manager network_data_loss_prevention
|
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers …
|
CWE-384
Session Fixation
|
CVE-2017-3968
|
2024-11-21 12:26 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250504
|
9.8 |
CRITICAL
Network
|
mcafee
|
network_security_manager
|
Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwor…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2017-3962
|
2024-11-21 12:26 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250505
|
8.8 |
HIGH
Network
|
mcafee
|
network_security_manager
|
Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to gain elevated privileges via a crafted HTT…
|
NVD-CWE-noinfo
|
CVE-2017-3960
|
2024-11-21 12:26 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250506
|
5.4 |
MEDIUM
Network
|
mcafee
|
network_security_manager
|
Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated users to allow arbitrary HTML code to be reflected in …
|
CWE-79
Cross-site Scripting
|
CVE-2017-3961
|
2024-11-21 12:26 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250507
|
6.4 |
MEDIUM
Physics
|
lenovo
|
flex_system_x240_m5_bios flex_system_x280_x6_bios flex_system_x480_x6_bios flex_system_x880_bios nextscale_nx360_m5_bios system_x3250_m6_bios system_x3500_m5_bios system_x3550_m5…
|
Some Lenovo System x server BIOS/UEFI versions, when Secure Boot mode is enabled by a system administrator, do not properly authenticate signed code before booting it. As a result, an attacker with p…
|
CWE-287
Improper Authentication
|
CVE-2017-3775
|
2024-11-21 12:26 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250508
|
7.5 |
HIGH
Network
|
vmware
|
xenon
|
VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient acces…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-4952
|
2024-11-21 12:26 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250509
|
7.5 |
HIGH
Network
|
lenovo
|
lenovo_help
|
Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observing the channel to potentially see this information.
|
CWE-200
Information Exposure
|
CVE-2017-3776
|
2024-11-21 12:26 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250510
|
9.8 |
CRITICAL
Network
|
lenovo
|
integrated_management_module_2
|
A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (IMM2) earlier than version 4.70 used in some Lenovo servers and earlier than ver…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-3774
|
2024-11-21 12:26 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|