|
258431
|
9.8 |
CRITICAL
Network
|
debian x.org
|
debian_linux xorg-server
|
xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2017-12183
|
2024-11-21 12:09 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258432
|
9.8 |
CRITICAL
Network
|
debian x.org
|
debian_linux xorg-server
|
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2017-12182
|
2024-11-21 12:09 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258433
|
9.8 |
CRITICAL
Network
|
debian x.org
|
debian_linux xorg-server
|
xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2017-12181
|
2024-11-21 12:09 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258434
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on t…
|
CWE-20
Improper Input Validation
|
CVE-2017-12632
|
2024-11-21 12:09 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258435
|
6.5 |
MEDIUM
Network
|
libpam4j_project redhat debian
|
libpam4j enterprise_linux debian_linux
|
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security re…
|
CWE-20
Improper Input Validation
|
CVE-2017-12197
|
2024-11-21 12:09 |
2018-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258436
|
6.1 |
MEDIUM
Network
|
cisco
|
sg350-10_firmware sg350-10p_firmware sg350-10mp_firmware sg355-10p_firmware sg350-28_firmware sg350-28p_firmware sg350-28mp_firmware sf350-48_firmware sf350-48p_firmware sf…
|
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack against a user of t…
|
NVD-CWE-Other
|
CVE-2017-12308
|
2024-11-21 12:09 |
2018-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258437
|
6.1 |
MEDIUM
Network
|
cisco
|
sg350-10_firmware sg350-10p_firmware sg350-10mp_firmware sg355-10p_firmware sg350-28_firmware sg350-28p_firmware sg350-28mp_firmware sf350-48_firmware sf350-48p_firmware sf…
|
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12307
|
2024-11-21 12:09 |
2018-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258438
|
7.8 |
HIGH
Local
|
redhat
|
jboss_enterprise_application_platform enterprise_linux
|
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This is…
|
NVD-CWE-noinfo
|
CVE-2017-12189
|
2024-11-21 12:09 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258439
|
7.1 |
HIGH
Network
|
apache
|
geode
|
When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status informati…
|
CWE-200
Information Exposure
|
CVE-2017-12622
|
2024-11-21 12:09 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258440
|
5.4 |
MEDIUM
Network
|
apache
|
drill
|
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting sp…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12630
|
2024-11-21 12:09 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|