|
250221
|
7.8 |
HIGH
Local
|
microsoft
|
excel excel_for_mac office_web_apps office_compatibility_pack
|
A remote code execution vulnerability exists in Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Offic…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8632
|
2024-11-21 12:34 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250222
|
7.8 |
HIGH
Local
|
microsoft
|
excel office_compatibility_pack office_web_apps office_online_server excel_viewer excel_web_app
|
A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT …
|
NVD-CWE-noinfo
|
CVE-2017-8631
|
2024-11-21 12:34 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250223
|
7.8 |
HIGH
Local
|
microsoft
|
excel_for_mac
|
A remote code execution vulnerability exists in Microsoft Excel for Mac 2011 when it fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution".
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8567
|
2024-11-21 12:34 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250224
|
5.5 |
MEDIUM
Local
|
blackwave
|
dive_assistant
|
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.
|
CWE-611
XXE
|
CVE-2017-8918
|
2024-11-21 12:34 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250225
|
5.3 |
MEDIUM
Network
|
elasticsearch
|
x-pack x-pack_reporting
|
The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role cou…
|
CWE-269
Improper Privilege Management
|
CVE-2017-8446
|
2024-11-21 12:34 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250226
|
5.5 |
MEDIUM
Local
|
elastic
|
x-pack
|
An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance that trusts all cert…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-8445
|
2024-11-21 12:34 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250227
|
7.8 |
HIGH
Local
|
microsoft
|
xamarin.ios
|
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vulnerability."
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-8665
|
2024-11-21 12:34 |
2017-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250228
|
9.8 |
CRITICAL
Network
|
microsoft
|
chakracore
|
A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8658
|
2024-11-21 12:34 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250229
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
Microsoft Edge allows a remote code execution vulnerability due to the way it accesses objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8518
|
2024-11-21 12:34 |
2017-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250230
|
8.8 |
HIGH
Network
|
microsoft
|
windows_7 windows_server_2008
|
Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow an attacker to execute code remotely on a target system when the Windows font library fails to properly handle specially crafted embedded f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8691
|
2024-11-21 12:34 |
2017-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|