|
198391
|
7.5 |
HIGH
Network
|
trendmicro
|
control_manager
|
Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-C…
|
CWE-200
Information Exposure
|
CVE-2017-11387
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198392
|
9.8 |
CRITICAL
Network
|
trendmicro
|
control_manager
|
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZD…
|
CWE-89
SQL Injection
|
CVE-2017-11386
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198393
|
9.8 |
CRITICAL
Network
|
trendmicro
|
control_manager
|
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN…
|
CWE-89
SQL Injection
|
CVE-2017-11385
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198394
|
9.8 |
CRITICAL
Network
|
trendmicro
|
control_manager
|
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN…
|
CWE-89
SQL Injection
|
CVE-2017-11384
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198395
|
9.8 |
CRITICAL
Network
|
trendmicro
|
control_manager
|
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN…
|
CWE-89
SQL Injection
|
CVE-2017-11383
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198396
|
6.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a …
|
CWE-269
Improper Privilege Management
|
CVE-2017-11438
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198397
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read reposi…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-11437
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198398
|
6.5 |
MEDIUM
Network
|
pega
|
pega_platform
|
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by lever…
|
CWE-200
Information Exposure
|
CVE-2017-11356
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198399
|
6.1 |
MEDIUM
Network
|
pega
|
pega_platform
|
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) …
|
CWE-79
Cross-site Scripting
|
CVE-2017-11355
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198400
|
4.4 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11334
|
2024-11-21 12:07 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|