|
249311
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, There is no synchronization between msm_vb2 buffer operations which can lead to use after fr…
|
CWE-416
Use After Free
|
CVE-2017-9704
|
2024-11-21 12:36 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249312
|
9.8 |
CRITICAL
Network
|
npci
|
bharat_interface_for_money_\(bhim\)
|
The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attac…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-9821
|
2024-11-21 12:36 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249313
|
9.8 |
CRITICAL
Network
|
npci
|
bharat_interface_for_money_\(bhim\)
|
The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Accessibility service, which makes it easier for attac…
|
CWE-287
Improper Authentication
|
CVE-2017-9820
|
2024-11-21 12:36 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249314
|
9.8 |
CRITICAL
Network
|
npci
|
bharat_interface_for_money_\(bhim\)
|
The National Payments Corporation of India BHIM application 1.3 for Android does not properly restrict use of the OTP feature, which makes it easier for attackers to bypass authentication.
|
CWE-287
Improper Authentication
|
CVE-2017-9819
|
2024-11-21 12:36 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249315
|
7.5 |
HIGH
Network
|
npci
|
bharat_interface_for_money_\(bhim\)
|
The National Payments Corporation of India BHIM application 1.3 for Android relies on a four-digit passcode, which makes it easier for attackers to obtain access.
|
CWE-521
Weak Password Requirements
|
CVE-2017-9818
|
2024-11-21 12:36 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249316
|
8.8 |
HIGH
Network
|
osisoft
|
pi_coresight
|
PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft recommends that users upgrade to PI Vision 2017 or greater to mitigate this vu…
|
CWE-352
Origin Validation Error
|
CVE-2017-9641
|
2024-11-21 12:36 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249317
|
9.8 |
CRITICAL
Network
|
abb
|
srea-50_firmware srea-01_firmware
|
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker may access internal files of ABB SREA-01 and SREA-50 legacy…
|
CWE-22
Path Traversal
|
CVE-2017-9664
|
2024-11-21 12:36 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249318
|
6.5 |
MEDIUM
Network
|
accellion
|
kiteworks
|
Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to …
|
CWE-287
Improper Authentication
|
CVE-2017-9421
|
2024-11-21 12:36 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249319
|
4.1 |
MEDIUM
Local
|
schneider-electric
|
ampla_manufacturing_execution_system
|
Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attac…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-9637
|
2024-11-21 12:36 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249320
|
3.9 |
LOW
Local
|
schneider-electric
|
ampla_manufacturing_execution_system
|
Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are configured to use Simple Security, a weakness in the password hashing algorithm …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-9635
|
2024-11-21 12:36 |
2018-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|