|
249201
|
7.5 |
HIGH
Network
|
atlassian
|
confluence_server
|
Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.
|
CWE-200
Information Exposure
|
CVE-2017-7415
|
2024-11-21 12:31 |
2017-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249202
|
7.8 |
HIGH
Local
|
dolby
|
dolby_audio_x2 dolby_audio_x3
|
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCO…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-7293
|
2024-11-21 12:31 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249203
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
Heap-based buffer overflow in drivers/net/macsec.c in the MACsec module in the Linux kernel through 4.10.12 allows attackers to cause a denial of service or possibly have unspecified other impact by …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7477
|
2024-11-21 12:31 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249204
|
8.8 |
HIGH
Network
|
opentext
|
documentum_content_server
|
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by levera…
|
CWE-89
SQL Injection
|
CVE-2017-7221
|
2024-11-21 12:31 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249205
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-70674.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7409
|
2024-11-21 12:31 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249206
|
8.8 |
HIGH
Network
|
opentext
|
documentum_content_server
|
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "…
|
CWE-20
Improper Input Validation
|
CVE-2017-7220
|
2024-11-21 12:31 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249207
|
8.8 |
HIGH
Network
|
unitrends
|
enterprise_backup
|
An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the…
|
CWE-20
Improper Input Validation
|
CVE-2017-7283
|
2024-11-21 12:31 |
2017-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249208
|
5.5 |
MEDIUM
Local
|
unitrends
|
enterprise_backup
|
An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This …
|
CWE-200
Information Exposure
|
CVE-2017-7282
|
2024-11-21 12:31 |
2017-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249209
|
9.1 |
CRITICAL
Network
|
atlassian
|
hipchat_server
|
Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-7357
|
2024-11-21 12:31 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249210
|
5.4 |
MEDIUM
Network
|
zurmo
|
zurmo_crm
|
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7188
|
2024-11-21 12:31 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|