|
198201
|
8.1 |
HIGH
Network
|
smiths-medical
|
medfusion_4000_wireless_syringe_infusion_pump
|
A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump does not verify inp…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12718
|
2024-11-21 12:10 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198202
|
9.8 |
CRITICAL
Network
|
moxa
|
softcms_lab_view
|
A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability has been identified…
|
CWE-89
SQL Injection
|
CVE-2017-12729
|
2024-11-21 12:10 |
2018-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198203
|
5.9 |
MEDIUM
Network
|
gm
|
shanghai_onstar
|
A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to intercept sensitiv…
|
CWE-200
Information Exposure
|
CVE-2017-12697
|
2024-11-21 12:10 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198204
|
8.8 |
HIGH
Network
|
gm
|
shanghai_onstar
|
An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to subvert sec…
|
CWE-287
Improper Authentication
|
CVE-2017-12695
|
2024-11-21 12:10 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198205
|
6.1 |
MEDIUM
Network
|
stivasoft
|
phpjabbers_file_sharing_script
|
PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12813
|
2024-11-21 12:10 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198206
|
6.1 |
MEDIUM
Network
|
stivasoft
|
phpjabbers_night_club_booking_software
|
PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12812
|
2024-11-21 12:10 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198207
|
6.1 |
MEDIUM
Network
|
stivasoft
|
phpjabbers_star_rating_script
|
PHPJabbers Star Rating Script 4.0 has stored XSS via a rating item.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12811
|
2024-11-21 12:10 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198208
|
6.1 |
MEDIUM
Network
|
stivasoft
|
phpjabbers_newsletter_script
|
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12810
|
2024-11-21 12:10 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198209
|
7.8 |
HIGH
Local
|
tracker-software
|
pdf-xchange_viewer
|
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.
|
CWE-20
Improper Input Validation
|
CVE-2017-13056
|
2024-11-21 12:10 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198210
|
7.5 |
HIGH
Network
|
siemens
|
simatic_s7-200_firmware simatic_s7-400pn_v6_firmware simatic_s7-400h_v6_firmware simatic_s7-400pn\/dp_v7_firmware simatic_s7-410_v8_firmware simatic_s7-300_firmware simatic_s7-1200_…
|
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
|
-
|
CVE-2017-12741
|
2024-11-21 12:10 |
2017-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|