|
249271
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to a WEBP_DECODER_ABI_VERSION check.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17880
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249272
|
8.8 |
HIGH
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based buffer over-read in ReadOneMNGImage in coders/png.c, related to length calculation and caused by an off-by-one error.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17879
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249273
|
9.8 |
CRITICAL
Network
|
valvesoftware
|
steam_link_firmware
|
An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka the CONFIG_FEATURE_DEFAULT_PASSWD_ALGO="des" settin…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2017-17878
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249274
|
9.8 |
CRITICAL
Network
|
valvesoftware
|
steam_link_firmware
|
An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless ad…
|
NVD-CWE-noinfo
|
CVE-2017-17877
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249275
|
7.5 |
HIGH
Network
|
iwcnetwork
|
shift
|
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter.
|
CWE-275
Permission Issues
|
CVE-2017-17876
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249276
|
9.8 |
CRITICAL
Network
|
jextn
|
jextn_faq_pro
|
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
|
CWE-89
SQL Injection
|
CVE-2017-17875
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249277
|
8.8 |
HIGH
Network
|
vanguard_project
|
marketplace_digital_products_php
|
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-17874
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249278
|
9.8 |
CRITICAL
Network
|
vanguard_project
|
marketplace_digital_products_php
|
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
|
CWE-89
SQL Injection
|
CVE-2017-17873
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249279
|
9.8 |
CRITICAL
Network
|
jextn
|
jextn_video_gallery
|
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
|
CWE-89
SQL Injection
|
CVE-2017-17872
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249280
|
9.8 |
CRITICAL
Network
|
jextn
|
jextn_question_and_answer
|
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17871
|
2024-11-21 12:18 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|