|
247231
|
7.5 |
HIGH
Network
|
tor_project debian
|
tor debian_linux
|
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion …
|
NVD-CWE-noinfo
|
CVE-2017-8819
|
2024-11-21 12:34 |
2017-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247232
|
9.8 |
CRITICAL
Network
|
haxx
|
libcurl curl
|
curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact because too litt…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8818
|
2024-11-21 12:34 |
2017-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247233
|
9.8 |
CRITICAL
Network
|
haxx debian
|
libcurl curl debian_linux
|
The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact v…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-8817
|
2024-11-21 12:34 |
2017-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247234
|
9.8 |
CRITICAL
Network
|
haxx debian
|
libcurl curl debian_linux
|
The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application cr…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-8816
|
2024-11-21 12:34 |
2017-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247235
|
9.8 |
CRITICAL
Network
|
cohuhd
|
3960hd_firmware
|
Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to the camera and cause malfunction or code execution, as dem…
|
CWE-693
Protection Mechanism Failure
|
CVE-2017-8864
|
2024-11-21 12:34 |
2017-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247236
|
7.5 |
HIGH
Network
|
cohuhd
|
3960hd_firmware
|
Information disclosure of .esp source code on the Cohu 3960 allows an attacker to view sensitive information such as application logic with a simple web browser.
|
CWE-200
Information Exposure
|
CVE-2017-8863
|
2024-11-21 12:34 |
2017-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247237
|
9.8 |
CRITICAL
Network
|
cohuhd
|
3960hd_firmware
|
The webupgrade function on the Cohu 3960HD does not verify the firmware upgrade files or process, allowing an attacker to upload a specially crafted postinstall.sh file that will be executed with "ro…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-8862
|
2024-11-21 12:34 |
2017-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247238
|
9.8 |
CRITICAL
Network
|
cohuhd
|
3960hd_firmware
|
Missing authentication for the remote configuration port 1236/tcp on the Cohu 3960HD allows an attacker to change configuration parameters such as IP address and username/password via specially craft…
|
CWE-287
Improper Authentication
|
CVE-2017-8861
|
2024-11-21 12:34 |
2017-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247239
|
6.5 |
MEDIUM
Network
|
cohuhd
|
3960hd_firmware
|
Information disclosure through directory listing on the Cohu 3960HD allows an attacker to view and download source code, log files, and other sensitive device information via a specially crafted web …
|
CWE-200
Information Exposure
|
CVE-2017-8860
|
2024-11-21 12:34 |
2017-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247240
|
9.1 |
CRITICAL
Network
|
varnish-cache varnish_cache_project debian
|
varnish varnish_cache debian_linux
|
vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a V…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8807
|
2024-11-21 12:34 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|