|
249091
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.
|
CWE-346
Origin Validation Error
|
CVE-2017-7667
|
2024-11-21 12:32 |
2017-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249092
|
6.1 |
MEDIUM
Network
|
apache
|
nifi
|
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7665
|
2024-11-21 12:32 |
2017-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249093
|
7.5 |
HIGH
Network
|
arm
|
arm_trusted_firmware
|
In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors involving debug except…
|
CWE-20
Improper Input Validation
|
CVE-2017-7564
|
2024-11-21 12:32 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249094
|
8.1 |
HIGH
Network
|
arm
|
arm_trusted_firmware
|
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency i…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-7563
|
2024-11-21 12:32 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249095
|
5.5 |
MEDIUM
Local
|
freedesktop
|
poppler
|
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.
|
CWE-674
Uncontrolled Recursion
|
CVE-2017-7515
|
2024-11-21 12:32 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249096
|
7.5 |
HIGH
Network
|
apache
|
hadoop
|
In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated u…
|
CWE-20
Improper Input Validation
|
CVE-2017-7669
|
2024-11-21 12:32 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249097
|
5.5 |
MEDIUM
Local
|
freedesktop
|
poppler
|
poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-7511
|
2024-11-21 12:32 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249098
|
7.5 |
HIGH
Network
|
mozilla
|
network_security_services
|
Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.
|
-
|
CVE-2017-7502
|
2024-11-21 12:32 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249099
|
8.8 |
HIGH
Network
|
moxa
|
oncell_g3110-hspa_firmware oncell_g3110-hsdpa_firmware oncell_g3150-hsdpa_firmware oncell_5104-hsdpa_firmware oncell_5104-hspa_firmware oncell_5004-hspa_firmware
|
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCe…
|
CWE-352
Origin Validation Error
|
CVE-2017-7917
|
2024-11-21 12:32 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249100
|
9.8 |
CRITICAL
Network
|
moxa
|
oncell_g3110-hspa_firmware oncell_g3110-hsdpa_firmware oncell_g3150-hsdpa_firmware oncell_5104-hsdpa_firmware oncell_5104-hspa_firmware oncell_5004-hspa_firmware
|
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 0912…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2017-7915
|
2024-11-21 12:32 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|