|
256771
|
5.5 |
MEDIUM
Local
|
skyboxsecurity
|
skybox_manager_client_application
|
Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password hashes. A local authenticated attacker can access the password hashes in a debu…
|
CWE-200
Information Exposure
|
CVE-2017-14770
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256772
|
9.8 |
CRITICAL
Network
|
opentext
|
document_sciences_xpression
|
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to an XML External Entity vulnerability: /xFramewo…
|
CWE-611
XXE
|
CVE-2017-14759
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256773
|
8.8 |
HIGH
Network
|
opentext
|
document_sciences_xpression
|
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.…
|
CWE-89
SQL Injection
|
CVE-2017-14758
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256774
|
8.8 |
HIGH
Network
|
opentext
|
document_sciences_xpression
|
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/down…
|
CWE-89
SQL Injection
|
CVE-2017-14757
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256775
|
6.1 |
MEDIUM
Network
|
opentext
|
document_sciences_xpression
|
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/Deployment (…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14756
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256776
|
6.1 |
MEDIUM
Network
|
opentext
|
document_sciences_xpression
|
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/XPressoDoc, …
|
CWE-79
Cross-site Scripting
|
CVE-2017-14755
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256777
|
6.5 |
MEDIUM
Network
|
opentext
|
document_sciences_xpression
|
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Arbitrary File Read: /xAdmin/html/cm_datasource…
|
CWE-22
Path Traversal
|
CVE-2017-14754
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256778
|
7.5 |
HIGH
Network
|
freedesktop debian
|
poppler debian_linux
|
The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to laun…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14977
|
2024-11-21 12:13 |
2017-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256779
|
7.5 |
HIGH
Network
|
freedesktop debian
|
poppler debian_linux
|
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an at…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-14976
|
2024-11-21 12:13 |
2017-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256780
|
7.5 |
HIGH
Network
|
freedesktop debian
|
poppler debian_linux
|
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14975
|
2024-11-21 12:13 |
2017-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|