|
246781
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, variable "ddp->params_length" could be accessed and modified by multiple threads, w…
|
CWE-119 CWE-362
Incorrect Access of Indexable Resource ('Range Error') Race Condition
|
CVE-2017-9677
|
2024-11-21 12:36 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246782
|
4.7 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and race conditions can occur when accessing global static variables without using a…
|
CWE-200 CWE-362 CWE-416
Information Exposure Race Condition Use After Free
|
CVE-2017-9676
|
2024-11-21 12:36 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246783
|
7.5 |
HIGH
Network
|
apache
|
struts
|
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which …
|
CWE-20
Improper Input Validation
|
CVE-2017-9804
|
2024-11-21 12:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246784
|
7.5 |
HIGH
Network
|
apache
|
struts
|
The REST Plugin in Apache Struts 2.1.x, 2.3.7 through 2.3.33 and 2.5 through 2.5.12 is using an outdated XStream library which is vulnerable and allow perform a DoS attack using malicious request wit…
|
CWE-20
Improper Input Validation
|
CVE-2017-9793
|
2024-11-21 12:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246785
|
5.0 |
MEDIUM
Adjacent
|
mirion_technologies
|
dmc_3000_firmware ipam_transmitter_f\/dmc_2000_firmware telepole_ii_firmware rds-31_itx_firmware rsd31-am_firmware wrm2_mesh_repeater_firmware drm-1\/2_firmware
|
A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-9649
|
2024-11-21 12:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246786
|
6.5 |
MEDIUM
Adjacent
|
mirion
|
dmc_3000_transmitter_firmware ipam_transmitter_f\/dmc_2000_firmware rds-31_itx_firmware drm-1\/2_firmware drm-2_firmware rds-31_firmware telepole_2_firmware wrm2_firmware
|
An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 a…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-9645
|
2024-11-21 12:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246787
|
7.0 |
HIGH
Local
|
arm
|
arm-trusted-firmware
|
The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-9607
|
2024-11-21 12:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246788
|
7.5 |
HIGH
Network
|
apache
|
solr
|
Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authentication of an end-user or another application. There are two issues with this…
|
CWE-287
Improper Authentication
|
CVE-2017-9803
|
2024-11-21 12:36 |
2017-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246789
|
7.5 |
HIGH
Network
|
apache debian
|
http_server debian_linux
|
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsb…
|
CWE-416
Use After Free
|
CVE-2017-9798
|
2024-11-21 12:36 |
2017-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246790
|
9.8 |
CRITICAL
Network
|
calendarscripts
|
watupro
|
SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action…
|
CWE-89
SQL Injection
|
CVE-2017-9834
|
2024-11-21 12:36 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|