|
257691
|
9.8 |
CRITICAL
Network
|
hp
|
storage_essentials
|
In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-10992
|
2024-11-21 12:06 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257692
|
8.8 |
HIGH
Network
|
ishekar
|
endoscope_camera_firmware
|
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruptio…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10724
|
2024-11-21 12:06 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257693
|
8.8 |
HIGH
Network
|
ishekar
|
endoscope_camera_firmware
|
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that an attacker connected to the device Wi-Fi SSID can exploit a memory corruptio…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10723
|
2024-11-21 12:06 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257694
|
7.8 |
HIGH
Local
|
ishekar
|
endoscope_camera_firmware
|
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack ov…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10722
|
2024-11-21 12:06 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257695
|
6.5 |
MEDIUM
Network
|
ishekar
|
endoscope_camera_firmware
|
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as a…
|
CWE-284
Improper Access Control
|
CVE-2017-10721
|
2024-11-21 12:06 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257696
|
7.8 |
HIGH
Local
|
ishekar
|
endoscope_camera_firmware
|
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack ov…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10720
|
2024-11-21 12:06 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257697
|
6.5 |
MEDIUM
Network
|
ishekar
|
endoscope_camera_firmware
|
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has default Wi-Fi credentials that are exactly the same for every …
|
CWE-200
Information Exposure
|
CVE-2017-10719
|
2024-11-21 12:06 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257698
|
6.5 |
MEDIUM
Network
|
ishekar
|
endoscope_camera_firmware
|
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that any malicious user connecting to the device can change the default SSID and p…
|
CWE-255
Credentials Management
|
CVE-2017-10718
|
2024-11-21 12:06 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257699
|
5.5 |
MEDIUM
Local
|
qualcomm
|
ipq8074_firmware mdm9206_firmware mdm9607_firmware mdm9635m_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware
|
A non-secure user may be able to access certain registers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU,…
|
NVD-CWE-noinfo
|
CVE-2017-11004
|
2024-11-21 12:06 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257700
|
7.5 |
HIGH
Network
|
zte
|
zxiptv-ucm_firmware
|
SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the d…
|
CWE-89
SQL Injection
|
CVE-2017-10937
|
2024-11-21 12:06 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|