Show filters
762 Total Results
Displaying 261-270 of 762
Sort by:
Attacker Value
Unknown

CVE-2017-13077

Disclosure Date: October 17, 2017 (last updated November 26, 2024)
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
0
Attacker Value
Unknown

CVE-2017-15041

Disclosure Date: October 05, 2017 (last updated November 26, 2024)
Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that example.com/pkg1 points to a Subversion repository but example.com/pkg1/pkg2 points to a Git repository. If the Subversion repository includes a Git checkout in its pkg2 directory and some other work is done to ensure the proper ordering of operations, "go get" can be tricked into reusing this Git checkout for the fetch of code from pkg2. If the Subversion repository's Git checkout has malicious commands in .git/hooks/, they will execute on the system running "go get."
Attacker Value
Unknown

CVE-2015-5184

Disclosure Date: September 25, 2017 (last updated November 08, 2023)
Console: CORS headers set to allow all in Red Hat AMQ.
Attacker Value
Unknown

CVE-2015-5183

Disclosure Date: September 25, 2017 (last updated November 08, 2023)
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
Attacker Value
Unknown

CVE-2015-7887

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.
0
Attacker Value
Unknown

CVE-2016-8743

Disclosure Date: July 27, 2017 (last updated November 08, 2023)
Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.
Attacker Value
Unknown

CVE-2017-9788

Disclosure Date: July 13, 2017 (last updated November 08, 2023)
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of uninitialized pool memory used by the prior request, leading to leakage of potentially confidential information, and a segfault in other cases resulting in denial of service.
0
Attacker Value
Unknown

CVE-2017-5878

Disclosure Date: June 08, 2017 (last updated November 26, 2024)
The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized Java data.
Attacker Value
Unknown

CVE-2017-5645

Disclosure Date: April 17, 2017 (last updated November 08, 2023)
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Attacker Value
Unknown

CVE-2017-0146

Disclosure Date: March 17, 2017 (last updated July 17, 2024)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.