CVE-2017-8153

CVSS v3 Score
7.1
High
CVSS v2 Score
5.8
Medium

Vulnerability Description

Huawei VMall (for Android) with the versions before 1.5.8.5 have a privilege elevation vulnerability due to improper design. An attacker can trick users into installing a malicious app which can send out HTTP requests and execute JavaScript code in web pages without obtaining the Internet access permission. Successful exploit could lead to resource occupation or information leak.

CVSS:7.1(High)

Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with so...

CVSS:7.2(High)

A vulnerability was found in CSZCMS 1.3.0 and classified as critical. Affected by this issue is some unknown functionality of the file \views\templates of the component File Manager Page. The manipula...

CVSS:6.7(Medium)

EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3.0 and 7.3.1 contain a vulnerability that may allow malicious administrators to compromise Avamar servers.

CVSS:6.7(Medium)

A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root privileges. The vulnera...

CVSS:7.5(High)

Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.

CVSS:7.5(High)

ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.