Show filters
1,598 Total Results
Displaying 321-330 of 1,598
Sort by:
Attacker Value
Unknown

CVE-2017-0815

Disclosure Date: October 04, 2017 (last updated November 26, 2024)
An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63526567.
0
Attacker Value
Unknown

CVE-2017-0814

Disclosure Date: October 04, 2017 (last updated November 26, 2024)
An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62800140.
0
Attacker Value
Unknown

CVE-2017-14496

Disclosure Date: October 03, 2017 (last updated November 08, 2023)
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
0
Attacker Value
Unknown

CVE-2017-11479

Disclosure Date: September 29, 2017 (last updated November 26, 2024)
Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
0
Attacker Value
Unknown

CVE-2017-8448

Disclosure Date: September 29, 2017 (last updated November 26, 2024)
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges.
0
Attacker Value
Unknown

CVE-2017-1591

Disclosure Date: September 28, 2017 (last updated November 26, 2024)
IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132368.
0
Attacker Value
Unknown

CVE-2017-1527

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 130156.
0
Attacker Value
Unknown

CVE-2017-1530

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409.
0
Attacker Value
Unknown

CVE-2017-1531

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130410.
0
Attacker Value
Unknown

CVE-2017-1539

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.
0