|
197801
|
6.5 |
MEDIUM
Network
|
netapp
|
oncommand_insight
|
NetApp OnCommand Insight version 7.3.0 and versions prior to 7.2.0 are susceptible to clickjacking attacks which could cause a user to perform an unintended action in the user interface.
|
CWE-20
Improper Input Validation
|
CVE-2017-13652
|
2024-11-21 12:11 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197802
|
4.6 |
MEDIUM
Physics
|
bostonscientific
|
zoom_latitude_prm_3120_firmware
|
Boston Scientific ZOOM LATITUDE PRM Model 3120 uses a hard-coded cryptographic key to encrypt PHI prior to having it transferred to removable media. CVSS v3 base score: 4.6; CVSS vector string: AV:P/…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-14014
|
2024-11-21 12:11 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197803
|
4.6 |
MEDIUM
Physics
|
bostonscientific
|
zoom_latitude_prm_3120_firmware
|
Boston Scientific ZOOM LATITUDE PRM Model 3120 does not encrypt PHI at rest. CVSS v3 base score: 4.6; CVSS vector string: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-14012
|
2024-11-21 12:11 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197804
|
7.8 |
HIGH
Local
|
spidercontrol
|
scada_microbrowser
|
In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path element vulnerability has been identified which could be exploited by placing a…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-14010
|
2024-11-21 12:11 |
2018-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197805
|
4.8 |
MEDIUM
Network
|
broadcom
|
advanced_secure_gateway symantec_proxysg
|
Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can inject arbitrary JavaScript code in the management cons…
|
CWE-79
Cross-site Scripting
|
CVE-2017-13678
|
2024-11-21 12:11 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197806
|
7.5 |
HIGH
Network
|
broadcom
|
advanced_secure_gateway symantec_proxysg
|
Denial-of-service (DoS) vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A remote attacker can use crafted HTTP/HTTPS requests to cause denial-of-service t…
|
NVD-CWE-noinfo
|
CVE-2017-13677
|
2024-11-21 12:11 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197807
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In alarm_ready_generic of alarm.cc, there is a possible out of bounds write due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. …
|
CWE-416
Use After Free
|
CVE-2017-13272
|
2024-11-21 12:11 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197808
|
7.3 |
HIGH
Network
|
google
|
android
|
A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69006799.
|
NVD-CWE-noinfo
|
CVE-2017-13271
|
2024-11-21 12:11 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197809
|
7.3 |
HIGH
Network
|
google
|
android
|
A elevation of privilege vulnerability in the upstream kernel mnh_sm driver. Product: Android. Versions: Android kernel. Android ID: A-69474744.
|
NVD-CWE-noinfo
|
CVE-2017-13270
|
2024-11-21 12:11 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197810
|
4.3 |
MEDIUM
Adjacent
|
google
|
android
|
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68818034.
|
CWE-200
Information Exposure
|
CVE-2017-13269
|
2024-11-21 12:11 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|