|
257401
|
9.8 |
CRITICAL
Network
|
ee
|
4gee_wifi_mbb_firmware
|
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices allow remote attackers to obtain sensitive information via a JSONP endpoint, as demonstrated by passwords and SMS content.
|
CWE-200
Information Exposure
|
CVE-2017-14269
|
2024-11-21 12:12 |
2017-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257402
|
6.1 |
MEDIUM
Network
|
ee
|
4gee_wifi_mbb_firmware
|
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have XSS in the sms_content parameter in a getSMSlist request.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14268
|
2024-11-21 12:12 |
2017-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257403
|
8.8 |
HIGH
Network
|
ee
|
4gee_wifi_mbb_firmware
|
EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have CSRF, related to goform/AddNewProfile, goform/setWanDisconnect, goform/setSMSAutoRedirectSetting, goform/setReset, and goform/uploadBackupSetti…
|
CWE-352
Origin Validation Error
|
CVE-2017-14267
|
2024-11-21 12:12 |
2017-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257404
|
9.8 |
CRITICAL
Network
|
libraw
|
libraw
|
A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution attack.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14265
|
2024-11-21 12:12 |
2017-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257405
|
8.1 |
HIGH
Network
|
samsung
|
srn_1670d_firmware srn_1000_firmware srn_472s_firmware srn_470d_firmware
|
On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUs…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-14262
|
2024-11-21 12:12 |
2017-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257406
|
7.8 |
HIGH
Local
|
bento4
|
bento4
|
In the SDK in Bento4 1.5.0-616, the AP4_StszAtom class in Ap4StszAtom.cpp file contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a crafted…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14261
|
2024-11-21 12:12 |
2017-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257407
|
7.8 |
HIGH
Local
|
axiosys
|
bento4
|
In the SDK in Bento4 1.5.0-616, the AP4_StssAtom class in Ap4StssAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arb…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14260
|
2024-11-21 12:12 |
2017-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257408
|
7.8 |
HIGH
Local
|
bento4
|
bento4
|
In the SDK in Bento4 1.5.0-616, the AP4_StscAtom class in Ap4StscAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arb…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14259
|
2024-11-21 12:12 |
2017-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257409
|
8.1 |
HIGH
Network
|
honeywell
|
enterprise_dvr_firmware maxpro_nvr_hybrid_se_firmware maxpro_nvr_hybrid_xe_firmware maxpro_nvr_se_firmware maxpro_nvr_xe_firmware fusion_iv_rev_c_firmware maxpro_nvr_pe_firmware
|
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userMana…
|
CWE-384
Session Fixation
|
CVE-2017-14263
|
2024-11-21 12:12 |
2017-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257410
|
7.8 |
HIGH
Local
|
bento4
|
bento4
|
In the SDK in Bento4 1.5.0-616, SetItemCount in Core/Ap4StscAtom.h file contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbit…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14258
|
2024-11-21 12:12 |
2017-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|