|
258211
|
9.8 |
CRITICAL
Network
|
spidercontrol
|
scada_microbrowser
|
A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Opening a maliciously crafted html file may cause a stack overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12707
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258212
|
7.5 |
HIGH
Network
|
spidercontrol
|
scada_web_server
|
A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files.
|
CWE-22
Path Traversal
|
CVE-2017-12694
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258213
|
5.3 |
MEDIUM
Local
|
westermo
|
mrd-305-din_firmware mrd-315-din_firmware mrd-355-din_firmware mrd-455-din_firmware
|
A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded credentials,…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-12709
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258214
|
8.8 |
HIGH
Network
|
westermo
|
mrd-305-din_firmware mrd-315-din_firmware mrd-355-din_firmware mrd-455-din_firmware
|
A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The application does not verif…
|
CWE-352
Origin Validation Error
|
CVE-2017-12703
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258215
|
5.4 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticated remote attackers to inject arbitrary …
|
CWE-79
Cross-site Scripting
|
CVE-2017-12879
|
2024-11-21 12:10 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258216
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
|
CWE-89
SQL Injection
|
CVE-2017-12679
|
2024-11-21 12:10 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258217
|
7.5 |
HIGH
Network
|
gnu canonical debian
|
cvs ubuntu_linux debian_linux
|
CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand…
|
NVD-CWE-noinfo
|
CVE-2017-12836
|
2024-11-21 12:10 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258218
|
6.3 |
MEDIUM
Local
|
nagios
|
nagios
|
Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-roo…
|
CWE-665
Improper Initialization
|
CVE-2017-12847
|
2024-11-21 12:10 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258219
|
6.1 |
MEDIUM
Network
|
apache2triad
|
apache2triad
|
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12971
|
2024-11-21 12:10 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258220
|
8.8 |
HIGH
Network
|
apache2triad
|
apache2triad
|
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts…
|
CWE-352
Origin Validation Error
|
CVE-2017-12970
|
2024-11-21 12:10 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|