|
198011
|
7.5 |
HIGH
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-13699
|
2024-11-21 12:11 |
2017-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198012
|
7.5 |
HIGH
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. An attacker could extract public and private keys from the firmware image available on the MOXA website and could use them agains…
|
NVD-CWE-noinfo
|
CVE-2017-13698
|
2024-11-21 12:11 |
2017-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198013
|
7.5 |
HIGH
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.
|
CWE-20
Improper Input Validation
|
CVE-2017-13703
|
2024-11-21 12:11 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198014
|
5.3 |
MEDIUM
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. Cookies can be stolen, manipulated, and reused.
|
CWE-200
Information Exposure
|
CVE-2017-13702
|
2024-11-21 12:11 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198015
|
4.8 |
MEDIUM
Network
|
moxa
|
eds-g512e_firmware
|
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface.
|
CWE-79
Cross-site Scripting
|
CVE-2017-13700
|
2024-11-21 12:11 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198016
|
8.8 |
HIGH
Network
|
libbpg_project
|
libbpg
|
The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-13136
|
2024-11-21 12:11 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198017
|
7.8 |
HIGH
Local
|
libbpg_project
|
libbpg
|
A NULL Pointer Dereference exists in VideoLAN x265, as used in libbpg 0.9.7 and other products, because the CUData::initialize function in common/cudata.cpp mishandles memory-allocation failure.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-13135
|
2024-11-21 12:11 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198018
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
wonderware_intouch wonderware_indusoft_web_studio
|
A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions, and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions. The …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14024
|
2024-11-21 12:11 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198019
|
7.8 |
HIGH
Local
|
automationdirect
|
click_plc_firmware c-more_plc_firmware c-more_micro_firmware gs_drives_fimware sl-soft_solo_temperature_controller_firmware
|
In AutomationDirect CLICK Programming Software (Part Number C0-PGMSW) Versions 2.10 and prior; C-More Programming Software (Part Number EA9-PGMSW) Versions 6.30 and prior; C-More Micro (Part Number E…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-14020
|
2024-11-21 12:11 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198020
|
3.3 |
LOW
Local
|
apple
|
iphone_os mac_os_x watchos tvos
|
An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the …
|
CWE-200
Information Exposure
|
CVE-2017-13852
|
2024-11-21 12:11 |
2017-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|