|
198051
|
6.1 |
MEDIUM
Network
|
hp
|
arcsight_enterprise_security_manager arcsight_enterprise_security_manager_express
|
A reflected Cross-Site Scripting(XSS) vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows for unintended information when a speci…
|
CWE-79
Cross-site Scripting
|
CVE-2017-13986
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198052
|
6.5 |
MEDIUM
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclos…
|
CWE-22
Path Traversal
|
CVE-2017-13985
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198053
|
6.5 |
MEDIUM
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet di…
|
CWE-287
Improper Authentication
|
CVE-2017-13984
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198054
|
9.8 |
CRITICAL
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to bypass authentication.
|
CWE-287
Improper Authentication
|
CVE-2017-13983
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198055
|
8.8 |
HIGH
Network
|
hp
|
bsm_platform_application_performance_management_system_health
|
A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files.
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2017-13982
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198056
|
7.8 |
HIGH
Local
|
unisys
|
mcp-firmware
|
Unisys Libra 64xx and 84xx and FS601 class systems with MCP-FIRMWARE before 43.211 allow remote authenticated users to cause a denial of service (program crash) or have unspecified other impact via v…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-13684
|
2024-11-21 12:11 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198057
|
7.0 |
HIGH
Local
|
norton
|
remove_\&_reinstall
|
Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious …
|
CWE-94
Code Injection
|
CVE-2017-13676
|
2024-11-21 12:11 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198058
|
8.8 |
HIGH
Network
|
digium
|
asterisk_gui
|
An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injection vulnerability has been identified that may al…
|
CWE-78
OS Command
|
CVE-2017-14001
|
2024-11-21 12:11 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198059
|
6.5 |
MEDIUM
Network
|
fastly
|
fastly
|
The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from authenticated session…
|
CWE-200
Information Exposure
|
CVE-2017-13761
|
2024-11-21 12:11 |
2017-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198060
|
7.8 |
HIGH
Local
|
gstn
|
india_goods_and_services_tax_network_offline_utility_tool
|
GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions.…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-13779
|
2024-11-21 12:11 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|