|
248621
|
6.1 |
MEDIUM
Network
|
atlassian
|
oauth
|
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-9506
|
2024-11-21 12:36 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248622
|
8.1 |
HIGH
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a WLAN driver can lead to a Use After Free condition.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2017-9685
|
2024-11-21 12:36 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248623
|
7.0 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in a USB driver can lead to a Use After Free condition.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2017-9684
|
2024-11-21 12:36 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248624
|
4.7 |
MEDIUM
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition in two KGSL driver functions can lead to a Use After Free condition.
|
CWE-200 CWE-362
Information Exposure Race Condition
|
CVE-2017-9682
|
2024-11-21 12:36 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248625
|
7.5 |
HIGH
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, if a pointer argument coming from userspace is invalid, a driver may use an uninitialized structure to log an error mes…
|
CWE-200
Information Exposure
|
CVE-2017-9680
|
2024-11-21 12:36 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248626
|
7.5 |
HIGH
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, if a userspace string is not NULL-terminated, kernel memory contents can leak to system logs.
|
CWE-200
Information Exposure
|
CVE-2017-9679
|
2024-11-21 12:36 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248627
|
7.8 |
HIGH
Local
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, in a video driver, memory corruption can potentially occur due to lack of bounds checking in a memcpy().
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9678
|
2024-11-21 12:36 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248628
|
6.1 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
Cross-site scripting (XSS) vulnerability in Paessler PRTG Network Monitor before 17.2.32.2279 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9816
|
2024-11-21 12:36 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248629
|
5.4 |
MEDIUM
Network
|
quali
|
cloudshell
|
Multiple cross-site scripting (XSS) vulnerabilities in Quali CloudShell before 8 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Name or (2) Description parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2017-9767
|
2024-11-21 12:36 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248630
|
7.5 |
HIGH
Network
|
resiprocate
|
resiprocate
|
Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted DN…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9454
|
2024-11-21 12:36 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|