|
252621
|
5.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to cause a denial of service (channel invisibility) via a misformatted post.
|
CWE-20
Improper Input Validation
|
CVE-2017-18873
|
2024-11-21 12:21 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252622
|
4.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-18872
|
2024-11-21 12:21 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252623
|
6.1 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. XSS attacks could occur against an OAuth 2.0 allow/deny page.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18877
|
2024-11-21 12:21 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252624
|
4.9 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can test for the existence of an arbitrary file.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-18876
|
2024-11-21 12:21 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252625
|
4.9 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2 when local storage for files is used. A System Admin can create arbitrary files.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-18875
|
2024-11-21 12:21 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252626
|
7.5 |
HIGH
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field n…
|
NVD-CWE-noinfo
|
CVE-2017-18871
|
2024-11-21 12:21 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252627
|
4.3 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, and 4.3.4. It mishandled webhook access control in the EnableOnlyAdminIntegrations case.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-18870
|
2024-11-21 12:21 |
2020-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252628
|
2.5 |
LOW
Local
|
chownr_project
|
chownr
|
A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2017-18869
|
2024-11-21 12:21 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252629
|
7.7 |
HIGH
Network
|
digi
|
xbee_2_firmware
|
Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack upon which the ZigBee protocol is built.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-18868
|
2024-11-21 12:21 |
2020-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252630
|
6.8 |
MEDIUM
Physics
|
netgear
|
d6100_firmware d7800_firmware r7100lg_firmware wndr4300_firmware wndr4500_firmware
|
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D6100 before 1.0.0.55, D7800 before V1.0.1.24, R7100LG before V1.0.0.32, WNDR4300v1 before 1.0.2.90,…
|
CWE-20
Improper Input Validation
|
CVE-2017-18867
|
2024-11-21 12:21 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|