|
252351
|
6.7 |
MEDIUM
Local
|
bitdefender
|
internet_security total_security antivirus_plus
|
Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-pro…
|
CWE-94
Code Injection
|
CVE-2017-6186
|
2024-11-21 12:29 |
2017-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252352
|
5.3 |
MEDIUM
Network
|
paloaltonetworks
|
terminal_services_agent
|
Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-6356
|
2024-11-21 12:29 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252353
|
7.5 |
HIGH
Network
|
opensuse sane-backends_project
|
leap sane-backends
|
saned in sane-backends 1.0.25 allows remote attackers to obtain sensitive memory information via a crafted SANE_NET_CONTROL_OPTION packet.
|
CWE-200
Information Exposure
|
CVE-2017-6318
|
2024-11-21 12:29 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252354
|
7.8 |
HIGH
Local
|
usbpcap_project
|
usbpcap
|
The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6178
|
2024-11-21 12:29 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252355
|
7.5 |
HIGH
Network
|
qemu
|
qemu
|
Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is enabled on the vmxnet3 device, allows remote attackers to cause a denial of se…
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-6058
|
2024-11-21 12:29 |
2017-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252356
|
5.3 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network an…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-6370
|
2024-11-21 12:29 |
2017-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252357
|
7.5 |
HIGH
Network
|
efssoft
|
easy_file_sharing_ftp_server
|
Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker to list and download any file from any folder outside the FTP root Directory.
|
CWE-22
Path Traversal
|
CVE-2017-6510
|
2024-11-21 12:29 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252358
|
8.1 |
HIGH
Network
|
drupal
|
drupal
|
A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, a…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2017-6381
|
2024-11-21 12:29 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252359
|
7.5 |
HIGH
Network
|
drupal
|
drupal
|
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that use…
|
CWE-352
Origin Validation Error
|
CVE-2017-6379
|
2024-11-21 12:29 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252360
|
7.5 |
HIGH
Network
|
drupal
|
drupal
|
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.
|
CWE-863
Incorrect Authorization
|
CVE-2017-6377
|
2024-11-21 12:29 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|