|
247201
|
9.8 |
CRITICAL
Network
|
mitsubishielectric
|
e-designer
|
Mitsubishi E-Designer, Version 7.52 Build 344 contains two code sections which may be exploited to allow an attacker to overwrite arbitrary memory locations. This can result in arbitrary code executi…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-9634
|
2024-11-21 12:36 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247202
|
8.8 |
HIGH
Network
|
dolibarr
|
dolibarr_erp\/crm
|
Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter).
|
CWE-89
SQL Injection
|
CVE-2017-9839
|
2024-11-21 12:36 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247203
|
5.4 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/ca…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9838
|
2024-11-21 12:36 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247204
|
7.8 |
HIGH
Local
|
google
|
android
|
The touchscreen driver synaptics_dsx in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-05, the size of a stack-allocated buffer can be set to a value which exceeds the size of th…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9723
|
2024-11-21 12:36 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247205
|
7.8 |
HIGH
Local
|
qcacld_2.0_project
|
qcacld_2.0
|
While parsing Netlink attributes in QCA_WLAN_VENDOR_ATTR_EXTSCAN_BSSID_HOTLIST_PARAMS_LOST_AP_SAMPLE_SIZE in qcacld 2.0 before 2017-05-16, a buffer overread could occur.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9694
|
2024-11-21 12:36 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247206
|
5.5 |
MEDIUM
Local
|
google
|
android
|
The length of attribute value for STA_EXT_CAPABILITY in __wlan_hdd_change_station in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-06 being less than the actual lenth of StaPara…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9693
|
2024-11-21 12:36 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247207
|
7.8 |
HIGH
Local
|
google
|
android
|
When an atomic commit is issued on a writeback panel with a NULL output_layer parameter in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-03, a NULL pointer dereference may poten…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-9692
|
2024-11-21 12:36 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247208
|
4.7 |
MEDIUM
Local
|
google
|
android
|
There is a race condition in Android for MSM, Firefox OS for MSM, and QRD Android that allows to access to already free'd memory in the debug message output functionality contained within the mobicor…
|
CWE-362
Race Condition
|
CVE-2017-9691
|
2024-11-21 12:36 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247209
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel memory address is passed from userspace through iris…
|
CWE-200
Information Exposure
|
CVE-2017-9681
|
2024-11-21 12:36 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247210
|
6.1 |
MEDIUM
Network
|
projectsend
|
projectsend
|
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the D…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9786
|
2024-11-21 12:36 |
2018-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|