|
249611
|
6.5 |
MEDIUM
Network
|
sandstorm
|
sandstorm
|
Sandstorm before build 0.203 allows remote attackers to read any specified file under /etc or /run via the sandbox backup function. The root cause is that the findFilesToZip function doesn't filter L…
|
CWE-200
Information Exposure
|
CVE-2017-6200
|
2024-11-21 12:29 |
2018-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249612
|
9.8 |
CRITICAL
Network
|
sandstorm
|
sandstorm
|
A remote attacker could bypass the Sandstorm organization restriction before build 0.203 via a comma in an email-address field.
|
CWE-287
Improper Authentication
|
CVE-2017-6199
|
2024-11-21 12:29 |
2018-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249613
|
6.5 |
MEDIUM
Network
|
sandstorm
|
sandstorm
|
The Supervisor in Sandstorm doesn't set and enforce the resource limits of a process. This allows remote attackers to cause a denial of service by launching a fork bomb in the sandbox, or by using a …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-6198
|
2024-11-21 12:29 |
2018-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249614
|
7.8 |
HIGH
Local
|
google
|
android
|
NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and could lead to local code execution in a privileged…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-6279
|
2024-11-21 12:29 |
2018-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249615
|
7.8 |
HIGH
Local
|
google
|
android
|
NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and could lead to local code execution in a privileged…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-6258
|
2024-11-21 12:29 |
2018-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249616
|
6.8 |
MEDIUM
Network
|
f5
|
big-ip_policy_enforcement_manager
|
In versions 13.0.0, 12.0.0-12.1.3, or 11.6.0-11.6.2, an F5 BIG-IP virtual server using the URL categorization feature may cause the Traffic Management Microkernel (TMM) to produce a core file when it…
|
CWE-20
Improper Input Validation
|
CVE-2017-6169
|
2024-11-21 12:29 |
2018-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249617
|
4.8 |
MEDIUM
Network
|
f5
|
big-ip_advanced_firewall_manager
|
X509 certificate verification was not correctly implemented in the early access "user id" feature in the F5 BIG-IP Advanced Firewall Manager versions 13.0.0, 12.1.0-12.1.2, and 11.6.0-11.6.2, and thu…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-6142
|
2024-11-21 12:29 |
2018-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249618
|
7.5 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to commands being execute…
|
CWE-362
Race Condition
|
CVE-2017-6167
|
2024-11-21 12:29 |
2017-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249619
|
8.1 |
HIGH
Network
|
f5
|
big-ip_local_traffic_manager big-ip_application_acceleration_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_access_policy_manager big-ip_application_security_manager<…
|
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator and WebSafe software version 13.0.0, 12.0.0 - 12.1.2, 11.6.0 - 11.6.1 and 11.5.0 - 11.5.4…
|
CWE-20
Improper Input Validation
|
CVE-2017-6164
|
2024-11-21 12:29 |
2017-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249620
|
5.9 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file can vary; customers r…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-6139
|
2024-11-21 12:29 |
2017-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|