|
247741
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
|
CWE-601
Open Redirect
|
CVE-2017-8451
|
2024-11-21 12:34 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247742
|
7.5 |
HIGH
Network
|
elastic
|
x-pack
|
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this infor…
|
CWE-200
Information Exposure
|
CVE-2017-8450
|
2024-11-21 12:34 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247743
|
5.9 |
MEDIUM
Network
|
elastic
|
x-pack
|
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field l…
|
CWE-200
Information Exposure
|
CVE-2017-8449
|
2024-11-21 12:34 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247744
|
7.8 |
HIGH
Local
|
microsoft
|
windows_xp windows_server_2003
|
Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially crafted file or program aka "Windows olecnv32.dll Remote Code Execution Vulnerabil…
|
NVD-CWE-noinfo
|
CVE-2017-8487
|
2024-11-21 12:34 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247745
|
7.8 |
HIGH
Local
|
microsoft
|
windows_xp windows_server_2003
|
Windows RPC with Routing and Remote Access enabled in Windows XP and Windows Server 2003 allows an attacker to execute code on a targeted RPC server which has Routing and Remote Access enabled via a …
|
NVD-CWE-noinfo
|
CVE-2017-8461
|
2024-11-21 12:34 |
2017-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247746
|
4.3 |
MEDIUM
Network
|
microsoft
|
edge
|
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certai…
|
CWE-20
Improper Input Validation
|
CVE-2017-8555
|
2024-11-21 12:34 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247747
|
4.7 |
MEDIUM
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_server_2016 windows_rt_8.1 windows_8.1
|
An information disclosure vulnerability exists in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows Server 2016 when the Windows …
|
CWE-200
Information Exposure
|
CVE-2017-8553
|
2024-11-21 12:34 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247748
|
7.8 |
HIGH
Local
|
microsoft
|
windows_7 windows_server_2008
|
A kernel-mode driver in Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows 8 allows an elevation of p…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2017-8552
|
2024-11-21 12:34 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247749
|
6.1 |
MEDIUM
Network
|
microsoft
|
project_server
|
An elevation of privilege vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint XSS vulnerability".
|
CWE-79
Cross-site Scripting
|
CVE-2017-8551
|
2024-11-21 12:34 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247750
|
5.4 |
MEDIUM
Network
|
microsoft
|
office
|
A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability".
|
CWE-79
Cross-site Scripting
|
CVE-2017-8550
|
2024-11-21 12:34 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|