|
248771
|
7.8 |
HIGH
Local
|
apple
|
iphone_os watchos mac_os_x tvos
|
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involve…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7027
|
2024-11-21 12:31 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248772
|
7.8 |
HIGH
Local
|
apple
|
iphone_os watchos mac_os_x tvos
|
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involve…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7026
|
2024-11-21 12:31 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248773
|
7.8 |
HIGH
Local
|
apple
|
safari iphone_os tvos icloud itunes
|
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involve…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7025
|
2024-11-21 12:31 |
2017-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248774
|
9.9 |
CRITICAL
Network
|
nfsen
|
nfsen
|
NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).
|
CWE-78
OS Command
|
CVE-2017-7175
|
2024-11-21 12:31 |
2017-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248775
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-615
|
The D-Link DIR-615 device before v20.12PTb04 doesn't use SSL for any of the authenticated pages. Also, it doesn't allow the user to generate his own SSL Certificate. An attacker can simply monitor ne…
|
CWE-295 CWE-311
Improper Certificate Validation Missing Encryption of Sensitive Data
|
CVE-2017-7406
|
2024-11-21 12:31 |
2017-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248776
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-615
|
On the D-Link DIR-615 before v20.12PTb04, once authenticated, this device identifies the user based on the IP address of his machine. By spoofing the IP address belonging to the victim's host, an att…
|
CWE-287
Improper Authentication
|
CVE-2017-7405
|
2024-11-21 12:31 |
2017-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248777
|
8.8 |
HIGH
Network
|
dlink
|
dir-615
|
On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site from another Browser tab, the malicious site then can send requests to the victim…
|
CWE-352
Origin Validation Error
|
CVE-2017-7404
|
2024-11-21 12:31 |
2017-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248778
|
6.1 |
MEDIUM
Network
|
topdesk
|
topdesk
|
There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7276
|
2024-11-21 12:31 |
2017-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248779
|
9.8 |
CRITICAL
Network
|
humaxdigital
|
hg100r_firmware
|
An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka GatewaySettings.bin.
|
CWE-200
Information Exposure
|
CVE-2017-7317
|
2024-11-21 12:31 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248780
|
6.1 |
MEDIUM
Network
|
humaxdigital
|
hg100r_firmware
|
An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7316
|
2024-11-21 12:31 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|