|
248761
|
7.5 |
HIGH
Network
|
ismartalarm
|
cubeone_firmware
|
iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.
|
CWE-20
Improper Input Validation
|
CVE-2017-7730
|
2024-11-21 12:32 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248762
|
7.5 |
HIGH
Network
|
ismartalarm
|
cubeone_firmware
|
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-7729
|
2024-11-21 12:32 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248763
|
9.8 |
CRITICAL
Network
|
ismartalarm
|
cubeone_firmware
|
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.
|
NVD-CWE-noinfo
|
CVE-2017-7728
|
2024-11-21 12:32 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248764
|
7.5 |
HIGH
Network
|
ismartalarm
|
cubeone_firmware
|
iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-7726
|
2024-11-21 12:32 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248765
|
7.5 |
HIGH
Network
|
apache
|
traffic_control
|
The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DNS port will remain …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-7670
|
2024-11-21 12:32 |
2017-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248766
|
9.8 |
CRITICAL
Network
|
redhat
|
3scale_api_management_platform
|
Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authenticatio…
|
CWE-863
Incorrect Authorization
|
CVE-2017-7512
|
2024-11-21 12:32 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248767
|
7.5 |
HIGH
Network
|
apache
|
solr
|
Apache Solr uses a PKI based mechanism to secure inter-node communication when security is enabled. It is possible to create a specially crafted node name that does not exist as part of the cluster a…
|
CWE-287
Improper Authentication
|
CVE-2017-7660
|
2024-11-21 12:32 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248768
|
7.8 |
HIGH
Local
|
windjview_project
|
windjview
|
WinDjView 2.1 might allow user-assisted attackers to execute code via a crafted .djvu file, because of a "User Mode Write AV near NULL" in WinDjView.exe. One threat model is a victim who obtains an u…
|
NVD-CWE-noinfo
|
CVE-2017-7894
|
2024-11-21 12:32 |
2017-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248769
|
9.8 |
CRITICAL
Network
|
newport
|
xps-cx_firmware xps-qx_firmware
|
An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific uniform resource locator (URL).
|
CWE-287
Improper Authentication
|
CVE-2017-7919
|
2024-11-21 12:32 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248770
|
9.8 |
CRITICAL
Network
|
ge
|
multilin_sr_750_feeder_protection_relay_firmware multilin_sr_760_feeder_protection_relay_firmware multilin_sr_469_motor_protection_relay_firmware multilin_sr_489_generator_protection_relay_f…
|
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmw…
|
CWE-326 CWE-330 CWE-522
Inadequate Encryption Strength Use of Insufficiently Random Values Insufficiently Protected Credentials
|
CVE-2017-7905
|
2024-11-21 12:32 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|