|
255641
|
7.8 |
HIGH
Local
|
apple
|
iphone_os watchos
|
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 11.2, watchOS 4.2. An application may be able to execute arbitrary code with kernel privilege.
|
NVD-CWE-noinfo
|
CVE-2017-13880
|
2024-11-21 12:11 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255642
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS High Sierra 10.13. An application may be able to execute arbitrary code with elevated privileges.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-13835
|
2024-11-21 12:11 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255643
|
9.8 |
CRITICAL
Network
|
amcrest
|
ipm-721s_firmware
|
The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera by using HTTP APIs, instead of the web management…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-13719
|
2024-11-21 12:11 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255644
|
8.0 |
HIGH
Network
|
starry
|
s00111_firmware
|
The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the device, and this allows an attacker to change the Wi-Fi settings and PIN, as well as…
|
CWE-254
7PK - Security Features
|
CVE-2017-13718
|
2024-11-21 12:11 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255645
|
8.8 |
HIGH
Network
|
starry
|
s00111_firmware
|
Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on any domain to make calls to the device's webserver and brute force the credential…
|
CWE-255
Credentials Management
|
CVE-2017-13717
|
2024-11-21 12:11 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255646
|
9.9 |
CRITICAL
Network
|
open-xchange
|
open-xchange_appsuite
|
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-13667
|
2024-11-21 12:11 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255647
|
5.4 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2017-13668
|
2024-11-21 12:11 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255648
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS X El Capitan 10.11.6 Security Update 2018-002, macOS Sierra 10.12.6 Security Update 2018-…
|
CWE-20
Improper Input Validation
|
CVE-2017-13911
|
2024-11-21 12:11 |
2019-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255649
|
6.5 |
MEDIUM
Network
|
apple
|
iphone_os
|
In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.
|
CWE-20
Improper Input Validation
|
CVE-2017-13891
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255650
|
9.8 |
CRITICAL
Network
|
apple
|
mac_os_x
|
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved…
|
CWE-287
Improper Authentication
|
CVE-2017-13889
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|