|
248001
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008
|
The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8718
|
2024-11-21 12:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248002
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008
|
The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8717
|
2024-11-21 12:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248003
|
7.0 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008
|
The Microsoft Windows Kernel Mode Driver on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and…
|
NVD-CWE-noinfo
|
CVE-2017-8694
|
2024-11-21 12:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248004
|
7.0 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008
|
The Microsoft Windows Kernel Mode Driver on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and…
|
NVD-CWE-noinfo
|
CVE-2017-8689
|
2024-11-21 12:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248005
|
8.8 |
HIGH
Network
|
elastic
|
x-pack
|
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privil…
|
CWE-269
Improper Privilege Management
|
CVE-2017-8448
|
2024-11-21 12:34 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248006
|
6.5 |
MEDIUM
Network
|
elastic
|
x-pack
|
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete an…
|
CWE-269
Improper Privilege Management
|
CVE-2017-8447
|
2024-11-21 12:34 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248007
|
5.9 |
MEDIUM
Network
|
elasticsearch
|
cloud_enterprise
|
The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the clien…
|
NVD-CWE-noinfo
|
CVE-2017-8444
|
2024-11-21 12:34 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248008
|
9.8 |
CRITICAL
Network
|
twsz
|
wifi_repeater_firmware
|
On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root") and can: 1. Read the entire file syst…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-8772
|
2024-11-21 12:34 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248009
|
9.8 |
CRITICAL
Network
|
twsz
|
wifi_repeater_firmware
|
On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root"). The attacker can make a user that is…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-8771
|
2024-11-21 12:34 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248010
|
7.5 |
HIGH
Network
|
twsz
|
wifi_repeater_firmware
|
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesystem on the device via a crafted getpage parameter.
|
CWE-200
Information Exposure
|
CVE-2017-8770
|
2024-11-21 12:34 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|