|
246751
|
9.8 |
CRITICAL
Network
|
juniper
|
junos
|
A remote, unauthenticated attacker may be able to execute code by exploiting a use-after-free defect found in older versions of PHP through injection of crafted data via specific PHP URLs within the …
|
CWE-416
Use After Free
|
CVE-2018-0001
|
2024-11-21 12:37 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246752
|
7.5 |
HIGH
Network
|
cisco
|
node-jose
|
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerabi…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-0114
|
2024-11-21 12:37 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246753
|
9.6 |
CRITICAL
Network
|
cisco
|
webex_meetings_server webex_meetings webex_business_suite webex_network_recording_player
|
A vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a remote attacker to execute arbitrary code on the system of a targeted user. The attacke…
|
CWE-20
Improper Input Validation
|
CVE-2018-0104
|
2024-11-21 12:37 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246754
|
7.8 |
HIGH
Local
|
cisco
|
webex_meetings_server webex_meetings webex_business_suite webex_network_recording_player
|
A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0103
|
2024-11-21 12:37 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246755
|
7.1 |
HIGH
Network
|
schneider-electric
|
pelco_videoxpert
|
A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges a…
|
NVD-CWE-noinfo
|
CVE-2017-9966
|
2024-11-21 12:37 |
2018-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246756
|
5.8 |
MEDIUM
Network
|
schneider-electric
|
pelco_videoxpert
|
An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can vi…
|
CWE-22
Path Traversal
|
CVE-2017-9965
|
2024-11-21 12:37 |
2018-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246757
|
6.9 |
MEDIUM
Network
|
schneider-electric
|
pelco_videoxpert
|
A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized person can execute a directory traversal…
|
CWE-22
Path Traversal
|
CVE-2017-9964
|
2024-11-21 12:37 |
2018-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246758
|
9.8 |
CRITICAL
Network
|
siemens
|
7kt_pac1200_data_manager_firmware
|
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticat…
|
CWE-269
Improper Privilege Management
|
CVE-2017-9944
|
2024-11-21 12:37 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246759
|
5.3 |
MEDIUM
Network
|
siemens
|
apogee_pxc_firmware apogee_pxc_modular_firmware talon_tc_compact_firmware talon_tc_modular_firmware
|
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with netw…
|
CWE-22
Path Traversal
|
CVE-2017-9947
|
2024-11-21 12:37 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246760
|
7.5 |
HIGH
Network
|
siemens
|
apogee_pxc_firmware apogee_pxc_modular_firmware talon_tc_compact_firmware talon_tc_modular_firmware
|
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 44…
|
CWE-287
Improper Authentication
|
CVE-2017-9946
|
2024-11-21 12:37 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|