|
247791
|
5.5 |
MEDIUM
Local
|
apple
|
iphone_os
|
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Sandbox Profiles" component. It allows attackers to bypass intended access restrictions (for iC…
|
NVD-CWE-noinfo
|
CVE-2017-6976
|
2024-11-21 12:30 |
2018-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247792
|
4.7 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. T…
|
CWE-601
Open Redirect
|
CVE-2017-6932
|
2024-11-21 12:30 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247793
|
6.5 |
MEDIUM
Network
|
drupal
|
drupal
|
In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for. If you have implemented…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-6931
|
2024-11-21 12:30 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247794
|
8.1 |
HIGH
Network
|
drupal
|
drupal
|
In Drupal versions 8.4.x versions before 8.4.5 when using node access controls with a multilingual site, Drupal marks the untranslated version of a node as the default fallback for access queries. Th…
|
NVD-CWE-noinfo
|
CVE-2017-6930
|
2024-11-21 12:30 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247795
|
6.1 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
A jQuery cross site scripting vulnerability is present when making Ajax requests to untrusted domains. This vulnerability is mitigated by the fact that it requires contributed or custom modules in or…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6929
|
2024-11-21 12:30 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247796
|
5.3 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
Drupal core 7.x versions before 7.57 when using Drupal's private file system, Drupal will check to make sure a user has access to a file before allowing the user to view or download it. This check fa…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-6928
|
2024-11-21 12:30 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247797
|
6.1 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
Drupal 8.4.x versions before 8.4.5 and Drupal 7.x versions before 7.57 has a Drupal.checkPlain() JavaScript function which is used to escape potentially dangerous text before outputting it to HTML (a…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6927
|
2024-11-21 12:30 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247798
|
8.1 |
HIGH
Network
|
drupal
|
drupal
|
In Drupal versions 8.4.x versions before 8.4.5 users with permission to post comments are able to view content and comments they do not have access to, and are also able to add comments to this conte…
|
CWE-200
Information Exposure
|
CVE-2017-6926
|
2024-11-21 12:30 |
2018-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247799
|
6.4 |
MEDIUM
Local
|
cisco
|
umbrella
|
The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (SSH) which auto initiated from the customer's appliance to Cisco's SSH Hubs in …
|
NVD-CWE-noinfo
|
CVE-2017-6679
|
2024-11-21 12:30 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247800
|
6.5 |
MEDIUM
Network
|
cisco
|
sf302-08pp_firmware sf302-08mpp_firmware sg300-10pp_firmware sg300-10mpp_firmware sf300-24pp_firmware sf300-48pp_firmware sg300-28pp_firmware sf300-08_firmware sf300-48p_firmw…
|
A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6720
|
2024-11-21 12:30 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|