|
247541
|
5.0 |
MEDIUM
Local
|
microsoft
|
windows_server_2008 windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1
|
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 all…
|
CWE-200
Information Exposure
|
CVE-2017-8462
|
2024-11-21 12:34 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247542
|
8.8 |
HIGH
Network
|
atlassian
|
bamboo
|
Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can…
|
CWE-863
Incorrect Authorization
|
CVE-2017-8907
|
2024-11-21 12:34 |
2017-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247543
|
6.5 |
MEDIUM
Network
|
gnome opensuse
|
libcroco leap
|
The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-8871
|
2024-11-21 12:34 |
2017-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247544
|
6.5 |
MEDIUM
Network
|
gnome opensuse
|
libcroco leap
|
The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8834
|
2024-11-21 12:34 |
2017-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247545
|
6.1 |
MEDIUM
Network
|
cgiirc
|
cgi\
|
irc.cgi in CGI:IRC before 0.5.12 reflects user-supplied input from the R parameter without proper output encoding, aka XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8920
|
2024-11-21 12:34 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247546
|
8.1 |
HIGH
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The attack methodology …
|
CWE-22
Path Traversal
|
CVE-2017-8841
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247547
|
5.3 |
MEDIUM
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request t…
|
CWE-200
Information Exposure
|
CVE-2017-8840
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247548
|
6.1 |
MEDIUM
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/p…
|
CWE-79
Cross-site Scripting
|
CVE-2017-8839
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247549
|
6.1 |
MEDIUM
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/H…
|
CWE-79
Cross-site Scripting
|
CVE-2017-8838
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247550
|
9.8 |
CRITICAL
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in questio…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-8837
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|