|
198011
|
4.9 |
MEDIUM
Network
|
synology
|
router_manager
|
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager (SRM) before 1.1.4-6509 allows remote authenticated attacker to exhaust the memory resourc…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-12077
|
2024-11-21 12:08 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198012
|
4.9 |
MEDIUM
Network
|
synology
|
diskstation_manager
|
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology DiskStation (DSM) before 6.1.1-15088 allows remote authenticated attacker to exhaust the memory resources…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-12076
|
2024-11-21 12:08 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198013
|
6.5 |
MEDIUM
Network
|
synology
|
dns_server
|
Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name…
|
CWE-22
Path Traversal
|
CVE-2017-12074
|
2024-11-21 12:08 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198014
|
8.8 |
HIGH
Local
|
xen citrix debian
|
xen xenserver debian_linux
|
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-12137
|
2024-11-21 12:08 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198015
|
7.8 |
HIGH
Local
|
xen citrix debian
|
xen xenserver debian_linux
|
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the hos…
|
CWE-362
Race Condition
|
CVE-2017-12136
|
2024-11-21 12:08 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198016
|
8.8 |
HIGH
Local
|
xen citrix debian
|
xen xenserver debian_linux
|
Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.
|
CWE-682
Incorrect Calculation
|
CVE-2017-12135
|
2024-11-21 12:08 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198017
|
8.8 |
HIGH
Local
|
xen citrix
|
xen xenserver
|
The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cau…
|
CWE-682
Incorrect Calculation
|
CVE-2017-12134
|
2024-11-21 12:08 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198018
|
8.8 |
HIGH
Network
|
supervisord fedoraproject debian redhat
|
supervisor fedora debian_linux cloudforms
|
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC req…
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-11610
|
2024-11-21 12:08 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198019
|
7.8 |
HIGH
Local
|
razer
|
synapse
|
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan horse (1) RazerConfigNative.dll or (2) RazerConfigNati…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-11653
|
2024-11-21 12:08 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198020
|
8.4 |
HIGH
Local
|
razer
|
synapse
|
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse dbghelp.dll file.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-11652
|
2024-11-21 12:08 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|