|
198111
|
7.8 |
HIGH
Local
|
i-sens
|
smartlog_diabetes_management_software
|
An Uncontrolled Search Path or Element issue was discovered in i-SENS SmartLog Diabetes Management Software, Version 2.4.0 and prior versions. An uncontrolled search path element vulnerability has be…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-13993
|
2024-11-21 12:11 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198112
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
wonderware_intouch wonderware_indusoft_web_studio
|
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio pro…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-13997
|
2024-11-21 12:11 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198113
|
7.5 |
HIGH
Network
|
redhat debian novell canonical fedoraproject thekelleys
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux leap ubuntu_linux fedora dnsmasq
|
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0x…
|
CWE-20
Improper Input Validation
|
CVE-2017-13704
|
2024-11-21 12:11 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198114
|
5.3 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.
|
CWE-200
Information Exposure
|
CVE-2017-13991
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198115
|
5.3 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.
|
CWE-200
Information Exposure
|
CVE-2017-13990
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198116
|
8.1 |
HIGH
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to retrieve or modify storage i…
|
NVD-CWE-noinfo
|
CVE-2017-13989
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198117
|
6.5 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows unauthorized users to alter the maximum size of st…
|
NVD-CWE-noinfo
|
CVE-2017-13988
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198118
|
6.5 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows an unauthorized user to download log files.
|
NVD-CWE-noinfo
|
CVE-2017-13987
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198119
|
6.1 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a speci…
|
CWE-79
Cross-site Scripting
|
CVE-2017-13986
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198120
|
6.5 |
MEDIUM
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclos…
|
CWE-22
Path Traversal
|
CVE-2017-13985
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|