|
258441
|
5.5 |
MEDIUM
Local
|
adobe
|
digital_editions
|
An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. Adobe Digital Editions parses crafted XML files in an unsafe manner, which could lead to sensitive information disclosure.
|
CWE-200
Information Exposure
|
CVE-2017-11273
|
2024-11-21 12:07 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258442
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an a…
|
CWE-601
Open Redirect
|
CVE-2017-11482
|
2024-11-21 12:07 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258443
|
6.1 |
MEDIUM
Network
|
elastic
|
kibana
|
Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11481
|
2024-11-21 12:07 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258444
|
7.5 |
HIGH
Network
|
elasticsearch
|
packetbeat
|
Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary …
|
NVD-CWE-noinfo
|
CVE-2017-11480
|
2024-11-21 12:07 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258445
|
9.8 |
CRITICAL
Network
|
redhat adobe
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation flash_player
|
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK metadata functionality. The mis…
|
CWE-416
Use After Free
|
CVE-2017-11225
|
2024-11-21 12:07 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258446
|
9.8 |
CRITICAL
Network
|
redhat adobe
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation flash_player
|
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability is an instance of a use after free vulnerability in the Primetime SDK. The mismatch between an old an…
|
CWE-416
Use After Free
|
CVE-2017-11215
|
2024-11-21 12:07 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258447
|
9.8 |
CRITICAL
Network
|
redhat adobe
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation flash_player
|
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to …
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11213
|
2024-11-21 12:07 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258448
|
7.0 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a video driver, a race condition exists which can potentially lead to a buffer overf…
|
CWE-119 CWE-362
Incorrect Access of Indexable Resource ('Range Error') Race Condition
|
CVE-2017-11049
|
2024-11-21 12:07 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258449
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a graphics driver ioctl handler, the lack of copy_from_user() function calls may res…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11047
|
2024-11-21 12:07 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258450
|
7.0 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a camera driver function, a race condition exists which can lead to a Use After Free…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2017-11045
|
2024-11-21 12:07 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|