|
255861
|
9.8 |
CRITICAL
Network
|
ismartalarm
|
cubeone_firmware
|
Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this…
|
CWE-200
Information Exposure
|
CVE-2017-13664
|
2024-11-21 12:11 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255862
|
7.5 |
HIGH
Network
|
ismartalarm
|
cubeone_firmware
|
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2017-13663
|
2024-11-21 12:11 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255863
|
8.1 |
HIGH
Network
|
apple
|
mac_os_x
|
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory Utility" component. It allows attackers to obtain a…
|
CWE-287
Improper Authentication
|
CVE-2017-13872
|
2024-11-21 12:11 |
2017-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255864
|
9.8 |
CRITICAL
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Indeed passwords are sto…
|
CWE-200
Information Exposure
|
CVE-2017-13701
|
2024-11-21 12:11 |
2017-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255865
|
7.5 |
HIGH
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-13699
|
2024-11-21 12:11 |
2017-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255866
|
7.5 |
HIGH
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. An attacker could extract public and private keys from the firmware image available on the MOXA website and could use them agains…
|
NVD-CWE-noinfo
|
CVE-2017-13698
|
2024-11-21 12:11 |
2017-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255867
|
7.5 |
HIGH
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.
|
CWE-20
Improper Input Validation
|
CVE-2017-13703
|
2024-11-21 12:11 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255868
|
5.3 |
MEDIUM
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. Cookies can be stolen, manipulated, and reused.
|
CWE-200
Information Exposure
|
CVE-2017-13702
|
2024-11-21 12:11 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255869
|
4.8 |
MEDIUM
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface.
|
CWE-79
Cross-site Scripting
|
CVE-2017-13700
|
2024-11-21 12:11 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255870
|
8.8 |
HIGH
Network
|
libbpg_project
|
libbpg
|
The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-13136
|
2024-11-21 12:11 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|