Vulnerabilities (CVE)

Filtered by CWE-200
Total 7434 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-2334 1 Juniper 1 Northstar Controller 2024-11-21 4.3 MEDIUM 7.5 HIGH
An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to perform a man-in-the-middle attack, thereby stealing authentic credentials from encrypted paths which are easily decrypted, and subsequently gain complete control of the system.
CVE-2017-2328 1 Juniper 1 Northstar Controller 2024-11-21 2.1 LOW 5.5 MEDIUM
An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to elevate their permissions through reading unprivileged information stored in the NorthStar controller.
CVE-2017-2326 1 Juniper 1 Northstar Controller 2024-11-21 6.8 MEDIUM 6.5 MEDIUM
An information disclosure vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, network-based attacker to replicate the underlying Junos OS VM and all data it maintains to their local system for future analysis.
CVE-2017-2320 1 Juniper 1 Northstar Controller 2024-11-21 10.0 HIGH 10.0 CRITICAL
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including managed systems, and full denial of services to any systems under management which NorthStar interacts with using read-only or read-write credentials.
CVE-2017-2318 1 Juniper 1 Northstar Controller 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to read log files which will compromise the integrity of the system, or provide elevation of privileges.
CVE-2017-2317 1 Juniper 1 Northstar Controller 2024-11-21 7.5 HIGH 8.6 HIGH
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential information disclosure, modification of system states, and partial to full denial of services relying upon data modified by an attacker.
CVE-2017-2309 1 Juniper 1 Junos Space 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.
CVE-2017-2304 1 Juniper 7 Ex4300, Ex4600, Junos and 4 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X53-D40, 15.1 prior to 15.1R2, do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is also known as 'Etherleak'
CVE-2017-2294 1 Puppet 1 Puppet Enterprise 2024-11-21 5.0 MEDIUM 7.5 HIGH
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore.
CVE-2017-2239 1 Marp 1 Marp 2024-11-21 6.8 MEDIUM 5.3 MEDIUM
Marp versions v0.0.10 and earlier may allow an attacker to access local resources and files using JavaScript.
CVE-2017-2180 1 Ipa 1 Appgoat 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors.
CVE-2017-2165 1 Groupsession 1 Groupsession 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as emails via unspecified vectors.
CVE-2017-2131 1 Panasonic 2 Kx-hjb1000, Kx-hjb1000 Firmware 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to bypass access restrictions to view the configuration menu via unspecified vectors.
CVE-2017-2109 1 Cybozu 1 Kunai 2024-11-21 2.6 LOW 2.5 LOW
Cybozu KUNAI for Android 3.0.4 to 3.0.5.1 allow remote attackers to obtain log information through a malicious Android application.
CVE-2017-2105 1 Presentcast Inc 1 Tver 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
The TVer App for Android 3.2.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-2104 1 K-opticom Corporation 1 Business Lala Call 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-2103 1 K-opticom Corporation 1 Lala Call 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-2093 1 Cybozu 1 Garoon 2024-11-21 4.3 MEDIUM 4.3 MEDIUM
Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.
CVE-2017-1785 1 Ibm 1 Api Connect 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters to obtain sensitive information. IBM X-Force ID: 136859.
CVE-2017-1784 2 Ibm, Netapp 2 Cognos Analytics, Oncommand Insight 2024-11-21 2.1 LOW 5.5 MEDIUM
IBM Cognos Analytics 11.0 could produce results in temporary files that contain highly sensitive information that can be read by a local user. IBM X-Force ID: 136858.