|
248091
|
7.8 |
HIGH
Local
|
cloudfoundry pivotal
|
cf-release capi-release
|
In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allo…
|
NVD-CWE-noinfo
|
CVE-2017-8048
|
2024-11-21 12:33 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248092
|
6.1 |
MEDIUM
Network
|
pivotal cloudfoundry
|
routing-release cf-release
|
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL…
|
CWE-601
Open Redirect
|
CVE-2017-8047
|
2024-11-21 12:33 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248093
|
9.8 |
CRITICAL
Network
|
dell
|
elastic_cloud_storage
|
EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially be leveraged by malicious users to compromise the affected system.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2017-8021
|
2024-11-21 12:33 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248094
|
7.5 |
HIGH
Network
|
emc
|
appsync
|
EMC AppSync host plug-in versions 3.5 and below (Windows platform only) includes a denial of service (DoS) vulnerability that could potentially be exploited by malicious users to compromise the affec…
|
CWE-20
Improper Input Validation
|
CVE-2017-8018
|
2024-11-21 12:33 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248095
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
u.motion_builder
|
A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and…
|
CWE-22
Path Traversal
|
CVE-2017-7974
|
2024-11-21 12:33 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248096
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
u.motion_builder
|
A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of…
|
CWE-89
SQL Injection
|
CVE-2017-7973
|
2024-11-21 12:33 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248097
|
5.5 |
MEDIUM
Adjacent
|
schneider-electric
|
powerscada_anywhere citect_anywhere
|
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to…
|
NVD-CWE-noinfo
|
CVE-2017-7972
|
2024-11-21 12:33 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248098
|
6.5 |
MEDIUM
Network
|
schneider-electric
|
powerscada_anywhere citect_anywhere
|
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of out…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-7971
|
2024-11-21 12:33 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248099
|
6.5 |
MEDIUM
Adjacent
|
schneider-electric
|
powerscada_anywhere citect_anywhere
|
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to…
|
NVD-CWE-noinfo
|
CVE-2017-7970
|
2024-11-21 12:33 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248100
|
8.8 |
HIGH
Network
|
schneider-electric
|
powerscada_anywhere citect_anywhere
|
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2…
|
CWE-352
Origin Validation Error
|
CVE-2017-7969
|
2024-11-21 12:33 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|