|
257421
|
6.5 |
MEDIUM
Network
|
synology
|
file_station
|
Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the dest_folder_path parame…
|
CWE-22
Path Traversal
|
CVE-2017-15893
|
2024-11-21 12:15 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257422
|
6.5 |
MEDIUM
Network
|
synology
|
calendar
|
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2017-15891
|
2024-11-21 12:15 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257423
|
7.8 |
HIGH
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a craf…
|
CWE-20
Improper Input Validation
|
CVE-2017-15868
|
2024-11-21 12:15 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257424
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overflow can occur while reading firmware logs.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15813
|
2024-11-21 12:15 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257425
|
8.8 |
HIGH
Network
|
synology
|
diskstation_manager
|
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
|
CWE-77
Command Injection
|
CVE-2017-15889
|
2024-11-21 12:15 |
2017-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257426
|
6.2 |
MEDIUM
Local
|
apache netapp oracle
|
struts oncommand_balance weblogic_server jd_edwards_enterpriseone_tools retail_xstore_point_of_service financial_services_market_risk_measurement_and_management webcenter_portal …
|
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
|
CWE-20
Improper Input Validation
|
CVE-2017-15707
|
2024-11-21 12:15 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257427
|
9.8 |
CRITICAL
Network
|
apache
|
qpid_broker-j
|
In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a rem…
|
NVD-CWE-noinfo
|
CVE-2017-15702
|
2024-11-21 12:15 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257428
|
7.5 |
HIGH
Network
|
apache
|
qpid_broker-j
|
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-15701
|
2024-11-21 12:15 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257429
|
8.8 |
HIGH
Network
|
otrs debian
|
otrs debian_linux
|
In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password.
|
NVD-CWE-noinfo
|
CVE-2017-15864
|
2024-11-21 12:15 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257430
|
7.5 |
HIGH
Network
|
konversation debian
|
konversation debian_linux
|
Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing of IRC color formatting codes.
|
NVD-CWE-noinfo
|
CVE-2017-15923
|
2024-11-21 12:15 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|