|
197721
|
9.8 |
CRITICAL
Network
|
amcrest
|
ipm-721s_firmware
|
The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various functionalities of the camera by using HTTP APIs, instead of the web management…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-13719
|
2024-11-21 12:11 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197722
|
8.0 |
HIGH
Network
|
starry
|
s00111_firmware
|
The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the device, and this allows an attacker to change the Wi-Fi settings and PIN, as well as…
|
CWE-254
7PK - Security Features
|
CVE-2017-13718
|
2024-11-21 12:11 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197723
|
8.8 |
HIGH
Network
|
starry
|
s00111_firmware
|
Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on any domain to make calls to the device's webserver and brute force the credential…
|
CWE-255
Credentials Management
|
CVE-2017-13717
|
2024-11-21 12:11 |
2019-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197724
|
9.9 |
CRITICAL
Network
|
open-xchange
|
open-xchange_appsuite
|
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-13667
|
2024-11-21 12:11 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197725
|
5.4 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2017-13668
|
2024-11-21 12:11 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197726
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS X El Capitan 10.11.6 Security Update 2018-002, macOS Sierra 10.12.6 Security Update 2018-…
|
CWE-20
Improper Input Validation
|
CVE-2017-13911
|
2024-11-21 12:11 |
2019-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197727
|
6.5 |
MEDIUM
Network
|
apple
|
iphone_os
|
In iOS before 11.2, an inconsistent user interface issue was addressed through improved state management.
|
CWE-20
Improper Input Validation
|
CVE-2017-13891
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197728
|
9.8 |
CRITICAL
Network
|
apple
|
mac_os_x
|
In macOS High Sierra before 10.13.3, Security Update 2018-001 Sierra, and Security Update 2018-001 El Capitan, a logic error existed in the validation of credentials. This was addressed with improved…
|
CWE-287
Improper Authentication
|
CVE-2017-13889
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197729
|
7.5 |
HIGH
Network
|
apple
|
iphone_os
|
In iOS before 11.2, a type confusion issue was addressed with improved memory handling.
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2017-13888
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197730
|
7.5 |
HIGH
Network
|
apple
|
mac_os_x
|
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation. This was addressed with improved state management.
|
CWE-320
Key Management Errors
|
CVE-2017-13887
|
2024-11-21 12:11 |
2019-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|