|
198021
|
6.7 |
MEDIUM
Local
|
progea
|
movicon
|
An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted search path or element vulnerability has been identified, which may allow an authori…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2017-14019
|
2024-11-21 12:11 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198022
|
7.8 |
HIGH
Local
|
progea
|
movicon
|
An Uncontrolled Search Path Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An uncontrolled search path element vulnerability has been identified, which may allow a remote…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-14017
|
2024-11-21 12:11 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198023
|
5.6 |
MEDIUM
Network
|
prominent
|
multiflex_m10a_controller_firmware
|
A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The log out function in the application removes the user's session only on…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2017-14013
|
2024-11-21 12:11 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198024
|
8.8 |
HIGH
Network
|
prominent
|
multiflex_m10a_controller_firmware
|
A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify requests, making it susceptible to cross-site requ…
|
CWE-352
Origin Validation Error
|
CVE-2017-14011
|
2024-11-21 12:11 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198025
|
6.5 |
MEDIUM
Network
|
prominent
|
multiflex_m10a_controller_firmware
|
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Password feature on the application, the current password…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-14009
|
2024-11-21 12:11 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198026
|
5.6 |
MEDIUM
Network
|
prominent
|
multiflex_m10a_controller_firmware
|
An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The user's session is available for an extended period beyond the last activity, allowing…
|
CWE-613
Insufficient Session Expiration
|
CVE-2017-14007
|
2024-11-21 12:11 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198027
|
8.8 |
HIGH
Network
|
prominent
|
multiflex_m10a_controller_firmware
|
An Unverified Password Change issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When setting a new password for a user, the application does not require the user to know the …
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2017-14005
|
2024-11-21 12:11 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198028
|
9.8 |
CRITICAL
Network
|
we-con
|
levi_studio_hmi_editor
|
A Stack-based Buffer Overflow issue was discovered in WECON LEVI Studio HMI Editor v1.8.1 and prior. Multiple stack-based buffer overflow vulnerabilities have been identified in which the application…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-13999
|
2024-11-21 12:11 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198029
|
9.8 |
CRITICAL
Network
|
lavalink
|
ether-serial_link_firmware
|
An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has…
|
CWE-287
Improper Authentication
|
CVE-2017-14003
|
2024-11-21 12:11 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198030
|
7.1 |
HIGH
Local
|
x.org
|
libxfont
|
In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xser…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-13722
|
2024-11-21 12:11 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|