|
250591
|
8.8 |
HIGH
Network
|
cambiumnetworks
|
epmp_1000_firmware epmp_2000_firmware
|
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-…
|
CWE-78
OS Command
|
CVE-2017-5255
|
2024-11-21 12:27 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250592
|
8.8 |
HIGH
Network
|
cambiumnetworks
|
epmp_1000_firmware epmp_2000_firmware
|
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after di…
|
CWE-269
Improper Privilege Management
|
CVE-2017-5254
|
2024-11-21 12:27 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250593
|
8.8 |
HIGH
Network
|
rapid7
|
nexpose
|
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site requ…
|
CWE-352
Origin Validation Error
|
CVE-2017-5264
|
2024-11-21 12:27 |
2017-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250594
|
8.8 |
HIGH
Network
|
tibco
|
tibbr
|
The tibbr user profiles components of tibbr Community, and tibbr Enterprise expose a weakness in an improperly sandboxed third-party component. Affected releases are TIBCO Software Inc. tibbr Communi…
|
NVD-CWE-noinfo
|
CVE-2017-5534
|
2024-11-21 12:27 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250595
|
8.1 |
HIGH
Network
|
tibco
|
tibbr
|
The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate thei…
|
NVD-CWE-noinfo
|
CVE-2017-5530
|
2024-11-21 12:27 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250596
|
9.8 |
CRITICAL
Network
|
tibco
|
jasperreports_server jaspersoft jaspersoft_reporting_and_analytics
|
A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with…
|
NVD-CWE-noinfo
|
CVE-2017-5533
|
2024-11-21 12:27 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250597
|
5.4 |
MEDIUM
Network
|
tibco
|
jasperreports_server jasperreports_library jaspersoft jaspersoft_reporting_and_analytics jaspersoft_studio
|
A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Libr…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5532
|
2024-11-21 12:27 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250598
|
5.7 |
MEDIUM
Adjacent
|
netapp
|
clustered_data_ontap
|
NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors, a different vulnerability tha…
|
CWE-200
Information Exposure
|
CVE-2017-5201
|
2024-11-21 12:27 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250599
|
8.8 |
HIGH
Network
|
google debian
|
chrome debian_linux
|
Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows allowed a remote attacker to trigger out-of-bounds access via a crafted HTML page.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5122
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250600
|
8.8 |
HIGH
Network
|
google debian redhat
|
chrome debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…
|
CWE-20
Improper Input Validation
|
CVE-2017-5121
|
2024-11-21 12:27 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|