Total
28 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-15706 | 1 Apache | 1 Tomcat | 2019-04-15 | 5.0 MEDIUM | 5.3 MEDIUM |
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. Note that the behaviour of the CGI servlet has remained unchanged in this regard. It is only the documentation of the behaviour that was wrong and has been corrected. | |||||
CVE-2017-7177 | 1 Openinfosecfoundation | 1 Suricata | 2018-12-05 | 5.0 MEDIUM | 7.5 HIGH |
Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching. | |||||
CVE-2017-15664 | 1 Flexense | 1 Syncbreeze | 2018-02-01 | 5.0 MEDIUM | 7.5 HIGH |
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9121. | |||||
CVE-2017-15663 | 1 Flexense | 1 Disk Pulse | 2018-02-01 | 5.0 MEDIUM | 7.5 HIGH |
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120. | |||||
CVE-2017-15662 | 1 Flexense | 1 Vx Search | 2018-02-01 | 5.0 MEDIUM | 7.5 HIGH |
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9123. | |||||
CVE-2017-15665 | 1 Flexense | 1 Diskboss | 2018-02-01 | 5.0 MEDIUM | 7.5 HIGH |
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094. | |||||
CVE-2017-8152 | 1 Huawei | 2 Honor 5s, Honor 5s Firmware | 2017-12-11 | 4.9 MEDIUM | 4.6 MEDIUM |
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory Reset Protection (FRP) bypass security vulnerability due to the improper design. An attacker can access factory reset page without authorization by only dial with special code. The attacker can exploit this vulnerability to restore the phone to factory settings. | |||||
CVE-2014-4843 | 1 Ibm | 1 Curam Social Program Management | 2017-06-15 | 5.0 MEDIUM | 5.3 MEDIUM |
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL. |