|
248301
|
6.5 |
MEDIUM
Network
|
gnome opensuse
|
libcroco leap
|
The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8834
|
2024-11-21 12:34 |
2017-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248302
|
6.1 |
MEDIUM
Network
|
cgiirc
|
cgi\
|
irc.cgi in CGI:IRC before 0.5.12 reflects user-supplied input from the R parameter without proper output encoding, aka XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8920
|
2024-11-21 12:34 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248303
|
8.1 |
HIGH
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The attack methodology …
|
CWE-22
Path Traversal
|
CVE-2017-8841
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248304
|
5.3 |
MEDIUM
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request t…
|
CWE-200
Information Exposure
|
CVE-2017-8840
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248305
|
6.1 |
MEDIUM
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/p…
|
CWE-79
Cross-site Scripting
|
CVE-2017-8839
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248306
|
6.1 |
MEDIUM
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/H…
|
CWE-79
Cross-site Scripting
|
CVE-2017-8838
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248307
|
9.8 |
CRITICAL
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in questio…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-8837
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248308
|
8.8 |
HIGH
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative inte…
|
CWE-352
Origin Validation Error
|
CVE-2017-8836
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248309
|
9.8 |
CRITICAL
Network
|
peplink
|
b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware
|
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth coo…
|
CWE-89
SQL Injection
|
CVE-2017-8835
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248310
|
4.3 |
MEDIUM
Network
|
elastic
|
x-pack
|
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases. This bug could allow a user with restricted permissions to view data…
|
CWE-200
Information Exposure
|
CVE-2017-8441
|
2024-11-21 12:34 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|