Show filters
73 Total Results
Displaying 61-70 of 73
Sort by:
Attacker Value
Unknown

CVE-2017-5243

Disclosure Date: June 06, 2017 (last updated November 26, 2024)
The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls back to allowing ALL algorithms supported by the relevant version of OpenSSH and makes the installations vulnerable to a range of MITM, downgrade, and decryption attacks.
0
Attacker Value
Unknown

CVE-2017-5236

Disclosure Date: May 03, 2017 (last updated November 26, 2024)
Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
0
Attacker Value
Unknown

CVE-2017-5240

Disclosure Date: May 03, 2017 (last updated November 26, 2024)
Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cause a denial of service condition when parsed by this component, causing the application to crash.
0
Attacker Value
Unknown

CVE-2017-5234

Disclosure Date: March 02, 2017 (last updated November 26, 2024)
Rapid7 Insight Collector installers prior to version 1.0.16 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
0
Attacker Value
Unknown

CVE-2017-5235

Disclosure Date: March 02, 2017 (last updated November 26, 2024)
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
0
Attacker Value
Unknown

CVE-2017-5233

Disclosure Date: March 02, 2017 (last updated November 26, 2024)
Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
Attacker Value
Unknown

CVE-2017-5229

Disclosure Date: March 02, 2017 (last updated November 26, 2024)
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
0
Attacker Value
Unknown

CVE-2017-5228

Disclosure Date: March 02, 2017 (last updated November 26, 2024)
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
0
Attacker Value
Unknown

CVE-2017-5231

Disclosure Date: March 02, 2017 (last updated November 26, 2024)
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.
0
Attacker Value
Unknown

CVE-2017-5230

Disclosure Date: March 02, 2017 (last updated November 26, 2024)
The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not modifiable by the user. The keystore provides storage for saved scan credentials in an otherwise secure location on disk.
0