|
250091
|
5.9 |
MEDIUM
Network
|
warnerbros
|
ellentube
|
The Warner Bros. ellentube app 3.1.1 through 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informat…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-8939
|
2024-11-21 12:35 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250092
|
5.9 |
MEDIUM
Network
|
radiojavan
|
radio_javan
|
The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a c…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-8938
|
2024-11-21 12:35 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250093
|
5.9 |
MEDIUM
Network
|
life_before_us
|
yo.
|
The Life Before Us Yo app 2.5.8 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted c…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-8937
|
2024-11-21 12:35 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250094
|
5.9 |
MEDIUM
Network
|
changyou
|
dolphin_web_browser
|
The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-8936
|
2024-11-21 12:35 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250095
|
5.9 |
MEDIUM
Network
|
gocivix
|
indiana_voters
|
The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive inf…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-8935
|
2024-11-21 12:35 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250096
|
5.5 |
MEDIUM
Local
|
pcmanfm_project
|
pcmanfm
|
PCManFM 1.2.5 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (application unavailability).
|
CWE-20
Improper Input Validation
|
CVE-2017-8934
|
2024-11-21 12:35 |
2017-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250097
|
3.3 |
LOW
Local
|
libmenu-cache_project
|
libmenu-cache
|
Libmenu-cache 1.0.2 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (menu unavailability).
|
CWE-20
Improper Input Validation
|
CVE-2017-8933
|
2024-11-21 12:35 |
2017-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250098
|
8.8 |
HIGH
Network
|
simpleinvoices
|
simple_invoices
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of admins for requests that can (1) create new administ…
|
CWE-352
Origin Validation Error
|
CVE-2017-8930
|
2024-11-21 12:35 |
2017-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250099
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule.
|
CWE-416
Use After Free
|
CVE-2017-8929
|
2024-11-21 12:35 |
2017-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250100
|
4.3 |
MEDIUM
Network
|
openstack
|
swift
|
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these log…
|
CWE-200
Information Exposure
|
CVE-2017-8761
|
2024-11-21 12:34 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|