|
257841
|
9.8 |
CRITICAL
Network
|
apache
|
commons_jelly
|
During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser insta…
|
CWE-611
XXE
|
CVE-2017-12621
|
2024-11-21 12:09 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257842
|
6.7 |
MEDIUM
Local
|
cisco
|
unified_computing_system
|
A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access. The vulnerability is due to insufficient input validation of commands enter…
|
CWE-20
Improper Input Validation
|
CVE-2017-12255
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257843
|
8.8 |
HIGH
Network
|
cisco
|
unified_intelligence_center
|
A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery …
|
CWE-352
Origin Validation Error
|
CVE-2017-12253
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257844
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_intelligence_center
|
A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack. T…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12254
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257845
|
7.8 |
HIGH
Local
|
cisco
|
findit_network_discovery_utility
|
A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to device availabil…
|
CWE-426
Untrusted Search Path
|
CVE-2017-12252
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257846
|
5.3 |
MEDIUM
Network
|
cisco
|
wide_area_application_services
|
A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an HTTP Application Optimization (AO) related proces…
|
CWE-20
Improper Input Validation
|
CVE-2017-12250
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257847
|
6.1 |
MEDIUM
Network
|
cisco
|
unified_intelligence_center
|
A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user o…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12248
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257848
|
7.5 |
HIGH
Network
|
cisco
|
spa_301_firmware spa_303_firmware spa_500ds_firmware spa_500s_firmware spa_501g_firmware spa_502g_firmware spa_504g_firmware spa_508g_firmware spa_509g_firmware spa_512g_fi…
|
A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload …
|
NVD-CWE-noinfo
|
CVE-2017-12219
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257849
|
7.1 |
HIGH
Local
|
cisco
|
asyncos
|
A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to …
|
CWE-20
Improper Input Validation
|
CVE-2017-12215
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257850
|
8.8 |
HIGH
Network
|
cisco
|
unified_customer_voice_portal
|
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remo…
|
CWE-20
Improper Input Validation
|
CVE-2017-12214
|
2024-11-21 12:09 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|