|
257841
|
4.7 |
MEDIUM
Local
|
x.org debian
|
xorg-server debian_linux
|
In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared mem…
|
CWE-269
Improper Privilege Management
|
CVE-2017-13721
|
2024-11-21 12:11 |
2017-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257842
|
7.5 |
HIGH
Network
|
loytec
|
lvis-3me_firmware
|
An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protect sensitive information from unauthorized access.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-13998
|
2024-11-21 12:11 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257843
|
8.8 |
HIGH
Network
|
loytec
|
lvis-3me_firmware
|
A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative users should not ha…
|
CWE-22
Path Traversal
|
CVE-2017-13996
|
2024-11-21 12:11 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257844
|
6.1 |
MEDIUM
Network
|
loytec
|
lvis-3me_firmware
|
A Cross-site Scripting issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web interface lacks proper web request validation, which could allow XSS attacks to occur if an authenticat…
|
CWE-79
Cross-site Scripting
|
CVE-2017-13994
|
2024-11-21 12:11 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257845
|
8.1 |
HIGH
Network
|
loytec
|
lvis-3me_firmware
|
An Insufficient Entropy issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not utilize sufficiently random number generation for the web interface authentication me…
|
CWE-331
Insufficient Entropy
|
CVE-2017-13992
|
2024-11-21 12:11 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257846
|
9.4 |
CRITICAL
Network
|
ctekproducts
|
skyrouter_z4200_firmware skyrouter_z4400_firmware
|
An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a specific uniform resource locator (URL) on the web server, a mal…
|
CWE-287
Improper Authentication
|
CVE-2017-14000
|
2024-11-21 12:11 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257847
|
10.0 |
CRITICAL
Network
|
spidercontrol
|
ininet_webserver
|
An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not properly authenticate users, which may allow a malicious…
|
CWE-287
Improper Authentication
|
CVE-2017-13995
|
2024-11-21 12:11 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257848
|
7.8 |
HIGH
Local
|
i-sens
|
smartlog_diabetes_management_software
|
An Uncontrolled Search Path or Element issue was discovered in i-SENS SmartLog Diabetes Management Software, Version 2.4.0 and prior versions. An uncontrolled search path element vulnerability has be…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-13993
|
2024-11-21 12:11 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257849
|
7.5 |
HIGH
Network
|
redhat debian novell canonical fedoraproject thekelleys
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux leap ubuntu_linux fedora dnsmasq
|
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0x…
|
CWE-20
Improper Input Validation
|
CVE-2017-13704
|
2024-11-21 12:11 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257850
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
wonderware_intouch wonderware_indusoft_web_studio
|
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio pro…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-13997
|
2024-11-21 12:11 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|