|
197791
|
8.8 |
HIGH
Network
|
starry
|
s00111_firmware
|
Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on any domain to make calls to the device's webserver and brute force the credential…
|
CWE-255
Credentials Management
|
CVE-2017-13717
|
2024-11-21 12:11 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197792
|
9.9 |
CRITICAL
Network
|
open-xchange
|
open-xchange_appsuite
|
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-13667
|
2024-11-21 12:11 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197793
|
5.4 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2017-13668
|
2024-11-21 12:11 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197794
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS X El Capitan 10.11.6 Security Update 2018-002, macOS Sierra 10.12.6 Security Update 2018-…
|
CWE-20
Improper Input Validation
|
CVE-2017-13911
|
2024-11-21 12:11 |
2019-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197795
|
6.5 |
MEDIUM
Network
|
apple
|
iphone_os
|
In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.
|
CWE-20
Improper Input Validation
|
CVE-2017-13891
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197796
|
9.8 |
CRITICAL
Network
|
apple
|
mac_os_x
|
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved…
|
CWE-287
Improper Authentication
|
CVE-2017-13889
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197797
|
7.5 |
HIGH
Network
|
apple
|
iphone_os
|
In iOS before 11.2, a type confusion issue was addressed with improved memory handling.
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2017-13888
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197798
|
7.5 |
HIGH
Network
|
apple
|
mac_os_x
|
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addressed with improved state management.
|
CWE-320
Key Management Errors
|
CVE-2017-13887
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197799
|
6.5 |
MEDIUM
Network
|
apple
|
mac_os_x
|
In macOS High Sierra before 10.13.2, an access issue existed with privileged WiFi system configuration. This issue was addressed with additional restrictions.
|
NVD-CWE-noinfo
|
CVE-2017-13886
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197800
|
7.5 |
HIGH
Network
|
iceqube
|
thermal_management_center_firmware
|
In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate users which may allow an attacker to gain access to sensitive information.
|
CWE-287
Improper Authentication
|
CVE-2017-14026
|
2024-11-21 12:11 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|