|
254741
|
9.8 |
CRITICAL
Network
|
gigabyte
|
gb-bsi7h-6500_firmware gb-bxi7-5775_firmware
|
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not…
|
CWE-20
Improper Input Validation
|
CVE-2017-3197
|
2024-11-21 12:25 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254742
|
9.8 |
CRITICAL
Network
|
themidnightcoders
|
weborb_for_java
|
The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. I…
|
CWE-611
XXE
|
CVE-2017-3208
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254743
|
9.8 |
CRITICAL
Network
|
themidnightcoders
|
weborb_for_java
|
The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class instances from java.io.Externalizable rather than the AMF3 specification's recommen…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3207
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254744
|
9.8 |
CRITICAL
Network
|
exadel
|
flamingo
|
The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If t…
|
CWE-611
XXE
|
CVE-2017-3206
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254745
|
8.1 |
HIGH
Network
|
pivotal
|
spring-flex
|
The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExt…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3203
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254746
|
8.1 |
HIGH
Network
|
exadel
|
flamingo_amf-serializer
|
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class instances from java.io.Externalizable rather than the AMF3 specification's recomme…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3201
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254747
|
8.1 |
HIGH
Network
|
graniteds
|
graniteds
|
The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExte…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3199
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254748
|
9.8 |
CRITICAL
Network
|
exadel
|
flamingo
|
The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes via their public parameter-less constructor and su…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3202
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254749
|
8.1 |
HIGH
Network
|
graniteds
|
graniteds
|
The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitr…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-3200
|
2024-11-21 12:25 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254750
|
7.8 |
HIGH
Local
|
rawether_project
|
rawether
|
PCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory outside of its typical bounds on the driver's receipt of networ…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-3196
|
2024-11-21 12:25 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|