|
247301
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9467
|
2024-11-21 12:36 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247302
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attacke…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9459
|
2024-11-21 12:36 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247303
|
6.6 |
MEDIUM
Physics
|
infineon
|
s-gold_2_pmb_8876
|
A Stack-Based Buffer Overflow issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-2010, Ford a limited number of P-HEV vehicles…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9647
|
2024-11-21 12:36 |
2017-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247304
|
8.8 |
HIGH
Adjacent
|
infineon
|
s-gold_2_pmb_8876
|
An Improper Restriction of Operations within the Bounds of a Memory Buffer issue was discovered in the Continental AG Infineon S-Gold 2 (PMB 8876) chipset on BMW several models produced between 2009-…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9633
|
2024-11-21 12:36 |
2017-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247305
|
9.8 |
CRITICAL
Network
|
pdqinc
|
laserwash_g5_firmware laserwash_g5_s_firmware laserwash_m5_firmware laserwash_360_firmware laserwash_360_plus_firmware laserwash_autoxpress_firmware laserwash_autoxpress_plus_firmwa…
|
A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, Laser…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-9632
|
2024-11-21 12:36 |
2017-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247306
|
9.4 |
CRITICAL
Network
|
pdqinc
|
laserwash_g5_firmware laserwash_g5_s_firmware laserwash_m5_firmware laserwash_360_firmware laserwash_360_plus_firmware laserwash_autoxpress_firmware laserwash_autoxpress_plus_firmwa…
|
An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpr…
|
CWE-287
Improper Authentication
|
CVE-2017-9630
|
2024-11-21 12:36 |
2017-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247307
|
9.8 |
CRITICAL
Network
|
sma
|
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t…
|
An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. The…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-9854
|
2024-11-21 12:36 |
2017-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247308
|
9.8 |
CRITICAL
Network
|
sma
|
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t…
|
An issue was discovered in SMA Solar Technology products. All inverters have a very weak password policy for the user and installer password. No complexity requirements or length requirements are set…
|
CWE-521
Weak Password Requirements
|
CVE-2017-9853
|
2024-11-21 12:36 |
2017-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247309
|
9.8 |
CRITICAL
Network
|
sma
|
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t…
|
An Incorrect Password Management issue was discovered in SMA Solar Technology products. Default passwords exist that are rarely changed. User passwords will almost always be default. Installer passwo…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-9852
|
2024-11-21 12:36 |
2017-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247310
|
7.5 |
HIGH
Network
|
spectrum
|
tc8717t_firmware
|
The Time Warner firmware on Technicolor TC8717T devices sets the default Wi-Fi passphrase to a combination of the SSID and BSSID, which makes it easier for remote attackers to obtain network access b…
|
NVD-CWE-noinfo
|
CVE-2017-9522
|
2024-11-21 12:36 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|