|
249011
|
6.5 |
MEDIUM
Network
|
eclipse debian
|
mosquitto debian_linux
|
In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or remotely connected clients to access MQTT topics that…
|
CWE-287
Improper Authentication
|
CVE-2017-7650
|
2024-11-21 12:32 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249012
|
9.8 |
CRITICAL
Network
|
eclipse
|
kura
|
The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be configured. Still the Equinox console port 5002 is le…
|
CWE-287
Improper Authentication
|
CVE-2017-7649
|
2024-11-21 12:32 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249013
|
6.1 |
MEDIUM
Network
|
icewarp
|
server
|
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7855
|
2024-11-21 12:32 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249014
|
6.5 |
MEDIUM
Network
|
riverbed
|
opnet_app_response_xpert
|
Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated users to inject arbitrary commands to read OS files.
|
CWE-22
Path Traversal
|
CVE-2017-7693
|
2024-11-21 12:32 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249015
|
5.9 |
MEDIUM
Network
|
osisoft
|
pi_data_archive
|
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older protocol versions contains a flaw that could allow a m…
|
CWE-287
Improper Authentication
|
CVE-2017-7934
|
2024-11-21 12:32 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249016
|
7.4 |
HIGH
Network
|
osisoft
|
pi_data_archive
|
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws with the potential to expose change records in the…
|
CWE-287
Improper Authentication
|
CVE-2017-7930
|
2024-11-21 12:32 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249017
|
8.8 |
HIGH
Network
|
osisoft
|
pi_web_api
|
A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur when an otherwise-u…
|
CWE-352
Origin Validation Error
|
CVE-2017-7926
|
2024-11-21 12:32 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249018
|
8.8 |
HIGH
Network
|
powerdns
|
dnsdist
|
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
|
CWE-352
Origin Validation Error
|
CVE-2017-7557
|
2024-11-21 12:32 |
2017-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249019
|
8.8 |
HIGH
Network
|
hawt
|
hawtio
|
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted …
|
CWE-352
Origin Validation Error
|
CVE-2017-7556
|
2024-11-21 12:32 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249020
|
9.8 |
CRITICAL
Network
|
augeas
|
augeas
|
Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the applicatio…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7555
|
2024-11-21 12:32 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|