|
253221
|
7.8 |
HIGH
Local
|
tianocore
|
edk2
|
Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escalation of privilege via local access.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5731
|
2024-11-21 12:28 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253222
|
6.5 |
MEDIUM
Network
|
libav
|
libav
|
In libavcodec in Libav 9.21, ff_h264_execute_ref_pic_marking() has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5984
|
2024-11-21 12:28 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253223
|
5.4 |
MEDIUM
Network
|
odoo
|
odoo
|
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
|
CWE-601
Open Redirect
|
CVE-2017-5871
|
2024-11-21 12:28 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253224
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2017-5864
|
2024-11-21 12:28 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253225
|
9.8 |
CRITICAL
Network
|
open-xchange
|
open-xchange_appsuite
|
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
|
CWE-284
Improper Access Control
|
CVE-2017-5863
|
2024-11-21 12:28 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253226
|
7.5 |
HIGH
Network
|
3m
|
detcon_sitewatch_gateway
|
Detcon Sitewatch Gateway, all versions without cellular, an attacker can edit settings on the device using a specially crafted URL.
|
CWE-287
Improper Authentication
|
CVE-2017-6049
|
2024-11-21 12:28 |
2019-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253227
|
9.8 |
CRITICAL
Network
|
3m
|
detcon_sitewatch_gateway
|
Detcon Sitewatch Gateway, all versions without cellular, Passwords are presented in plaintext in a file that is accessible without authentication.
|
CWE-255
Credentials Management
|
CVE-2017-6047
|
2024-11-21 12:28 |
2019-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253228
|
6.1 |
MEDIUM
Network
|
moinmo debian canonical opensuse
|
moinmoin debian_linux ubuntu_linux leap
|
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5934
|
2024-11-21 12:28 |
2018-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253229
|
5.3 |
MEDIUM
Network
|
apache
|
pony_mail
|
The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private list…
|
CWE-200
Information Exposure
|
CVE-2017-5658
|
2024-11-21 12:28 |
2018-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253230
|
5.5 |
MEDIUM
Local
|
intel
|
graphics_driver
|
Out-of-bounds read condition in older versions of some Intel Graphics Driver for Windows code branches allows local users to perform a denial of service attack.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5692
|
2024-11-21 12:28 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|