|
247781
|
5.4 |
MEDIUM
Network
|
hitachi
|
device_manager
|
Cross-site scripting vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to execute arbitrary JavaScript code.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9298
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247782
|
6.1 |
MEDIUM
Network
|
hitachi
|
device_manager
|
Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to redirect users to arbitrary web sites.
|
CWE-601
Open Redirect
|
CVE-2017-9297
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247783
|
6.1 |
MEDIUM
Network
|
hitachi
|
device_manager
|
Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows remote attackers to redirect authenticated users to arbitrary web sites.
|
CWE-601
Open Redirect
|
CVE-2017-9296
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247784
|
6.5 |
MEDIUM
Network
|
hitachi
|
device_manager
|
XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files.
|
CWE-611
XXE
|
CVE-2017-9295
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247785
|
9.8 |
CRITICAL
Network
|
hitachi
|
device_manager
|
RMI vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to execute internal commands without authentication via RMI ports.
|
NVD-CWE-noinfo
|
CVE-2017-9294
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247786
|
6.1 |
MEDIUM
Network
|
lansweeper
|
lansweeper
|
Lansweeper before 6.0.0.65 has XSS in an image retrieval URI, aka Bug 542782.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9292
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247787
|
6.1 |
MEDIUM
Network
|
note_project
|
note
|
Bram Korsten Note through 1.2.0 is vulnerable to a reflected XSS in note-source\ui\editor.php (edit parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-9289
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247788
|
9.8 |
CRITICAL
Network
|
freeradius
|
freeradius
|
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, …
|
CWE-287
Improper Authentication
|
CVE-2017-9148
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247789
|
6.1 |
MEDIUM
Network
|
raygun
|
raygun4wp
|
The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected XSS in sendtesterror.php (backurl parameter).
|
CWE-79
Cross-site Scripting
|
CVE-2017-9288
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247790
|
6.5 |
MEDIUM
Network
|
openldap debian redhat mcafee oracle
|
openldap debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_eus enterprise_linux_server_tus
|
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged …
|
CWE-415
Double Free
|
CVE-2017-9287
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|