|
198741
|
7.8 |
HIGH
Local
|
cisco
|
identity_services_engine identity_services_engine_express identity_services_engine_virtual_appliance
|
A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated…
|
CWE-863
Incorrect Authorization
|
CVE-2017-12261
|
2024-11-21 12:09 |
2017-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198742
|
7.8 |
HIGH
Local
|
cisco
|
unified_computing_system_manager_firmware firepower_9300_security_appliance_firmware firepower_4100_next-generation_firewall_firmware
|
A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authentica…
|
CWE-78
OS Command
|
CVE-2017-12243
|
2024-11-21 12:09 |
2017-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198743
|
4.3 |
MEDIUM
Network
|
apache
|
hive
|
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view…
|
CWE-200
Information Exposure
|
CVE-2017-12625
|
2024-11-21 12:09 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198744
|
5.4 |
MEDIUM
Network
|
barco
|
clickshare_csm-1_firmware clickshare_csc-1_firmware
|
An issue was discovered in Barco ClickShare CSM-1 firmware before v1.7.0.3 and CSC-1 firmware before v1.10.0.10. An authenticated user can manage the wallpaper collection in the webUI to be shown as…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12460
|
2024-11-21 12:09 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198745
|
4.7 |
MEDIUM
Local
|
apache
|
portable_runtime_utility
|
Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A loc…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12618
|
2024-11-21 12:09 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198746
|
7.1 |
HIGH
Local
|
apache debian redhat
|
portable_runtime debian_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server software_colle…
|
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting t…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12613
|
2024-11-21 12:09 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198747
|
6.7 |
MEDIUM
Local
|
cisco
|
advanced_malware_protection
|
The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-12317
|
2024-11-21 12:09 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198748
|
7.8 |
HIGH
Local
|
apache
|
james_server
|
The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX soc…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-12628
|
2024-11-21 12:09 |
2017-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198749
|
7.8 |
HIGH
Local
|
hashicorp
|
vagrant_vmware_fusion
|
An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-12579
|
2024-11-21 12:09 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198750
|
8.8 |
HIGH
Network
|
cisco
|
spa300_firmware spa500_firmware
|
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cr…
|
CWE-352
Origin Validation Error
|
CVE-2017-12271
|
2024-11-21 12:09 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|