|
198401
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
Heap-based buffer overflow in enhance.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-12876
|
2024-11-21 12:10 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198402
|
7.8 |
HIGH
Local
|
deslock
|
deslock\+
|
A kernel driver, namely DLMFENC.sys, bundled with the DESLock+ client application 4.8.16 and earlier contains a locally exploitable heap based buffer overflow in the handling of an IOCTL message of t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12840
|
2024-11-21 12:10 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198403
|
7.5 |
HIGH
Network
|
kaspersky
|
internet_security
|
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-12817
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198404
|
9.8 |
CRITICAL
Network
|
kaspersky
|
internet_security
|
In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the p…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-12816
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198405
|
8.8 |
HIGH
Network
|
polycom
|
unified_communications_software
|
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application.…
|
CWE-200
Information Exposure
|
CVE-2017-12857
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198406
|
9.8 |
CRITICAL
Network
|
spidercontrol
|
scada_microbrowser
|
A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Opening a maliciously crafted html file may cause a stack overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12707
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198407
|
7.5 |
HIGH
Network
|
spidercontrol
|
scada_web_server
|
A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files.
|
CWE-22
Path Traversal
|
CVE-2017-12694
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198408
|
5.3 |
MEDIUM
Local
|
westermo
|
mrd-305-din_firmware mrd-315-din_firmware mrd-355-din_firmware mrd-455-din_firmware
|
A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded credentials,…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-12709
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198409
|
8.8 |
HIGH
Network
|
westermo
|
mrd-305-din_firmware mrd-315-din_firmware mrd-355-din_firmware mrd-455-din_firmware
|
A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The application does not verif…
|
CWE-352
Origin Validation Error
|
CVE-2017-12703
|
2024-11-21 12:10 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198410
|
5.4 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticated remote attackers to inject arbitrary …
|
CWE-79
Cross-site Scripting
|
CVE-2017-12879
|
2024-11-21 12:10 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|