|
249751
|
9.0 |
CRITICAL
Network
|
intel
|
nuc7i3bnk_bios nuc7i5bnk_bios nuc7i7bnh_bios stk2mv64cc_bios stk2m3w64cc_bios nuc6i7kyk_bios nuc6i3syk_bios nuc6i5syk_bios r1304sposhor_bios r1304sposhorr_bios r1208spos…
|
Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows…
|
NVD-CWE-noinfo
|
CVE-2017-5691
|
2024-11-21 12:28 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249752
|
7.0 |
HIGH
Local
|
waves
|
maxxaudio
|
Waves MaxxAudio, as installed on Dell laptops, adds a "WavesSysSvc" Windows service with File Version 1.1.6.0. This service has a vulnerability known as Unquoted Service Path. This could potentially …
|
NVD-CWE-noinfo
|
CVE-2017-6005
|
2024-11-21 12:28 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249753
|
7.5 |
HIGH
Network
|
apache
|
impala
|
During a routine security analysis, it was found that one of the ports in Apache Impala (incubating) 2.7.0 to 2.8.0 sent data in plaintext even when the cluster was configured to use TLS. The port in…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-5652
|
2024-11-21 12:28 |
2017-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249754
|
9.8 |
CRITICAL
Network
|
apache
|
impala
|
It was noticed that a malicious process impersonating an Impala daemon in Apache Impala (incubating) 2.7.0 to 2.8.0 could cause Impala daemons to skip authentication checks when Kerberos is enabled (…
|
CWE-287
Improper Authentication
|
CVE-2017-5640
|
2024-11-21 12:28 |
2017-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249755
|
8.8 |
HIGH
Network
|
bestpractical
|
request_tracker
|
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authenticated users with certain privileges to execute a…
|
CWE-20
Improper Input Validation
|
CVE-2017-5944
|
2024-11-21 12:28 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249756
|
8.8 |
HIGH
Network
|
bestpractical
|
request_tracker
|
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site request forgery (CSRF) verification tokens…
|
CWE-352
Origin Validation Error
|
CVE-2017-5943
|
2024-11-21 12:28 |
2017-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249757
|
7.5 |
HIGH
Network
|
sierra_wireless
|
airlink_raven_xe_firmware airlink_raven_xt_firmware
|
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive informati…
|
CWE-200
Information Exposure
|
CVE-2017-6046
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249758
|
9.8 |
CRITICAL
Network
|
sierra_wireless
|
airlink_raven_xe_firmware airlink_raven_xt_firmware
|
An Improper Authorization issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Several files and directories can…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-6044
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249759
|
8.8 |
HIGH
Network
|
sierra_wireless
|
airlink_raven_xe_firmware airlink_raven_xt_firmware
|
A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify…
|
CWE-352
Origin Validation Error
|
CVE-2017-6042
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249760
|
5.3 |
MEDIUM
Network
|
belden_hirschmann
|
gecko_lite_managed_switch_firmware
|
An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive information can be obtained anonymously.
|
CWE-200
Information Exposure
|
CVE-2017-6040
|
2024-11-21 12:28 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|