|
248481
|
5.9 |
MEDIUM
Local
|
grails
|
pdf_plugin
|
XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.
|
CWE-611
XXE
|
CVE-2017-6344
|
2024-11-21 12:29 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248482
|
8.1 |
HIGH
Network
|
dahuasecurity
|
camera_firmware nvr_firmware smartpss_firmware
|
The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attac…
|
CWE-287
Improper Authentication
|
CVE-2017-6343
|
2024-11-21 12:29 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248483
|
5.9 |
MEDIUM
Network
|
dahuasecurity
|
camera_firmware nvr_firmware smartpss_firmware
|
Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-6341
|
2024-11-21 12:29 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248484
|
9.8 |
CRITICAL
Network
|
dahuasecurity
|
camera_firmware nvr_firmware smartpss_firmware
|
An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19. When SmartPS…
|
CWE-269
Improper Privilege Management
|
CVE-2017-6342
|
2024-11-21 12:29 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248485
|
5.9 |
MEDIUM
Network
|
mikrotik
|
routeros
|
The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-6297
|
2024-11-21 12:29 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248486
|
7.8 |
HIGH
Local
|
tnef_project debian
|
tnef debian_linux
|
An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-6310
|
2024-11-21 12:29 |
2017-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248487
|
7.8 |
HIGH
Local
|
tnef_project debian
|
tnef debian_linux
|
An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-6309
|
2024-11-21 12:29 |
2017-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248488
|
7.8 |
HIGH
Local
|
tnef_project debian
|
tnef debian_linux
|
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-6308
|
2024-11-21 12:29 |
2017-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248489
|
7.8 |
HIGH
Local
|
tnef_project debian
|
tnef debian_linux
|
An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, controlled by an attacke…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-6307
|
2024-11-21 12:29 |
2017-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248490
|
7.8 |
HIGH
Local
|
ytnef_project debian
|
ytnef debian_linux
|
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilename function in settings.c."
|
CWE-22
Path Traversal
|
CVE-2017-6306
|
2024-11-21 12:29 |
2017-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|