|
198641
|
7.5 |
HIGH
Network
|
apache
|
nifi
|
A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and compare to a controlled whitelist was applied on t…
|
CWE-20
Improper Input Validation
|
CVE-2017-12632
|
2024-11-21 12:09 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198642
|
6.5 |
MEDIUM
Network
|
libpam4j_project redhat debian
|
libpam4j enterprise_linux debian_linux
|
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security re…
|
CWE-20
Improper Input Validation
|
CVE-2017-12197
|
2024-11-21 12:09 |
2018-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198643
|
6.1 |
MEDIUM
Network
|
cisco
|
sg350-10_firmware sg350-10p_firmware sg350-10mp_firmware sg355-10p_firmware sg350-28_firmware sg350-28p_firmware sg350-28mp_firmware sf350-48_firmware sf350-48p_firmware sf…
|
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack against a user of t…
|
NVD-CWE-Other
|
CVE-2017-12308
|
2024-11-21 12:09 |
2018-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198644
|
6.1 |
MEDIUM
Network
|
cisco
|
sg350-10_firmware sg350-10p_firmware sg350-10mp_firmware sg355-10p_firmware sg350-28_firmware sg350-28p_firmware sg350-28mp_firmware sf350-48_firmware sf350-48p_firmware sf…
|
A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12307
|
2024-11-21 12:09 |
2018-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198645
|
7.8 |
HIGH
Local
|
redhat
|
jboss_enterprise_application_platform enterprise_linux
|
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This is…
|
NVD-CWE-noinfo
|
CVE-2017-12189
|
2024-11-21 12:09 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198646
|
7.1 |
HIGH
Network
|
apache
|
geode
|
When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with HTTP, the user is able to obtain status informati…
|
CWE-200
Information Exposure
|
CVE-2017-12622
|
2024-11-21 12:09 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198647
|
5.4 |
MEDIUM
Network
|
apache
|
drill
|
In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting sp…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12630
|
2024-11-21 12:09 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198648
|
5.9 |
MEDIUM
Network
|
cisco
|
adaptive_security_appliance_5505_firmware adaptive_security_appliance_5510_firmware adaptive_security_appliance_5520_firmware adaptive_security_appliance_5540_firmware adaptive_security_a…
|
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive i…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2017-12373
|
2024-11-21 12:09 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198649
|
8.8 |
HIGH
Network
|
apache
|
cxf_fediz
|
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, S…
|
CWE-352
Origin Validation Error
|
CVE-2017-12631
|
2024-11-21 12:09 |
2017-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198650
|
9.6 |
CRITICAL
Network
|
cisco
|
webex_meetings_server webex_meetings
|
A "Cisco WebEx Network Recording Player Remote Code Execution Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files.…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12372
|
2024-11-21 12:09 |
2017-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|