|
252721
|
7.5 |
HIGH
Network
|
starscream_project
|
starscream
|
WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function).
|
CWE-295
Improper Certificate Validation
|
CVE-2017-5887
|
2024-11-21 12:28 |
2017-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252722
|
7.5 |
HIGH
Network
|
apache
|
geode
|
Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the…
|
CWE-200
Information Exposure
|
CVE-2017-5649
|
2024-11-21 12:28 |
2017-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252723
|
4.6 |
MEDIUM
Physics
|
riverbed
|
rios
|
Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw di…
|
CWE-200
Information Exposure
|
CVE-2017-5670
|
2024-11-21 12:28 |
2017-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252724
|
7.8 |
HIGH
Local
|
intel
|
hardware_accelerated_execution_manager
|
Privilege escalation in IntelHAXM.sys driver in the Intel Hardware Accelerated Execution Manager before version 6.0.6 allows a local user to gain system level access.
|
NVD-CWE-noinfo
|
CVE-2017-5683
|
2024-11-21 12:28 |
2017-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252725
|
3.9 |
LOW
Physics
|
intel
|
nuc6i3syh_bios nuc6i3syk_bios
|
The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version SY0059 may allow may allow an attacker with physical access to the system to gain access to personal information.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-5686
|
2024-11-21 12:28 |
2017-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252726
|
3.9 |
LOW
Physics
|
intel
|
nuc6i7kyk_bios
|
The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version KY0045 may allow may allow an attacker with physical access to the system to gain access to personal information.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-5685
|
2024-11-21 12:28 |
2017-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252727
|
3.9 |
LOW
Physics
|
intel
|
stk2mv64cc_bios
|
The BIOS in Intel Compute Stick systems based on 6th Gen Intel Core processors prior to version CC047 may allow an attacker with physical access to the system to gain access to personal information.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-5684
|
2024-11-21 12:28 |
2017-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252728
|
9.8 |
CRITICAL
Network
|
apache
|
ambari
|
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-5642
|
2024-11-21 12:28 |
2017-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252729
|
5.5 |
MEDIUM
Local
|
artifex
|
ghostscript
|
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-5951
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252730
|
5.5 |
MEDIUM
Local
|
yaml-cpp_project
|
yaml-cpp
|
The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5950
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|