Total
7434 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-2334 | 1 Juniper | 1 Northstar Controller | 2024-11-21 | 4.3 MEDIUM | 7.5 HIGH |
An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to perform a man-in-the-middle attack, thereby stealing authentic credentials from encrypted paths which are easily decrypted, and subsequently gain complete control of the system. | |||||
CVE-2017-2328 | 1 Juniper | 1 Northstar Controller | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to elevate their permissions through reading unprivileged information stored in the NorthStar controller. | |||||
CVE-2017-2326 | 1 Juniper | 1 Northstar Controller | 2024-11-21 | 6.8 MEDIUM | 6.5 MEDIUM |
An information disclosure vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, network-based attacker to replicate the underlying Junos OS VM and all data it maintains to their local system for future analysis. | |||||
CVE-2017-2320 | 1 Juniper | 1 Northstar Controller | 2024-11-21 | 10.0 HIGH | 10.0 CRITICAL |
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including managed systems, and full denial of services to any systems under management which NorthStar interacts with using read-only or read-write credentials. | |||||
CVE-2017-2318 | 1 Juniper | 1 Northstar Controller | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to read log files which will compromise the integrity of the system, or provide elevation of privileges. | |||||
CVE-2017-2317 | 1 Juniper | 1 Northstar Controller | 2024-11-21 | 7.5 HIGH | 8.6 HIGH |
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential information disclosure, modification of system states, and partial to full denial of services relying upon data modified by an attacker. | |||||
CVE-2017-2309 | 1 Juniper | 1 Junos Space | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk. | |||||
CVE-2017-2304 | 1 Juniper | 7 Ex4300, Ex4600, Junos and 4 more | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X53-D40, 15.1 prior to 15.1R2, do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is also known as 'Etherleak' | |||||
CVE-2017-2294 | 1 Puppet | 1 Puppet Enterprise | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore. | |||||
CVE-2017-2239 | 1 Marp | 1 Marp | 2024-11-21 | 6.8 MEDIUM | 5.3 MEDIUM |
Marp versions v0.0.10 and earlier may allow an attacker to access local resources and files using JavaScript. | |||||
CVE-2017-2180 | 1 Ipa | 1 Appgoat | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors. | |||||
CVE-2017-2165 | 1 Groupsession | 1 Groupsession | 2024-11-21 | 4.0 MEDIUM | 6.5 MEDIUM |
GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as emails via unspecified vectors. | |||||
CVE-2017-2131 | 1 Panasonic | 2 Kx-hjb1000, Kx-hjb1000 Firmware | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to bypass access restrictions to view the configuration menu via unspecified vectors. | |||||
CVE-2017-2109 | 1 Cybozu | 1 Kunai | 2024-11-21 | 2.6 LOW | 2.5 LOW |
Cybozu KUNAI for Android 3.0.4 to 3.0.5.1 allow remote attackers to obtain log information through a malicious Android application. | |||||
CVE-2017-2105 | 1 Presentcast Inc | 1 Tver | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
The TVer App for Android 3.2.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2017-2104 | 1 K-opticom Corporation | 1 Business Lala Call | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2017-2103 | 1 K-opticom Corporation | 1 Lala Call | 2024-11-21 | 4.3 MEDIUM | 5.9 MEDIUM |
The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
CVE-2017-2093 | 1 Cybozu | 1 Garoon | 2024-11-21 | 4.3 MEDIUM | 4.3 MEDIUM |
Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors. | |||||
CVE-2017-1785 | 1 Ibm | 1 Api Connect | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters to obtain sensitive information. IBM X-Force ID: 136859. | |||||
CVE-2017-1784 | 2 Ibm, Netapp | 2 Cognos Analytics, Oncommand Insight | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-Force ID: 136858. |