|
253991
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value.
|
CWE-369
Divide By Zero
|
CVE-2017-9344
|
2024-11-21 12:35 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253992
|
7.5 |
HIGH
Network
|
wireshark
|
wireshark
|
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a NULL pointer. This was addressed in epan/dissectors/packet-msnip.c by validating an IPv4 address.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-9343
|
2024-11-21 12:35 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253993
|
5.5 |
MEDIUM
Local
|
qemu
|
qemu
|
Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (memory consumption) via a large nu…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2017-9060
|
2024-11-21 12:35 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253994
|
6.1 |
MEDIUM
Network
|
markdown_on_save_improved_project
|
markdown_on_save_improved
|
The Markdown on Save Improved plugin 2.5 for WordPress has a stored XSS vulnerability in the content of a post.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9337
|
2024-11-21 12:35 |
2017-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253995
|
6.1 |
MEDIUM
Network
|
wp_editor.md_project
|
wp_editor.md
|
The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9336
|
2024-11-21 12:35 |
2017-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253996
|
7.5 |
HIGH
Network
|
call-cc
|
chicken
|
An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, which allows an attacker to cause a denial of servic…
|
CWE-20
Improper Input Validation
|
CVE-2017-9334
|
2024-11-21 12:35 |
2017-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253997
|
5.4 |
MEDIUM
Network
|
epesi
|
epesi
|
The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows remote attackers t…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9331
|
2024-11-21 12:35 |
2017-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253998
|
6.5 |
MEDIUM
Network
|
allen_disk_project
|
allen_disk
|
SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-9307
|
2024-11-21 12:35 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253999
|
6.1 |
MEDIUM
Network
|
syspass
|
syspass
|
inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" substring.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9306
|
2024-11-21 12:35 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254000
|
6.1 |
MEDIUM
Network
|
tiki
|
tikiwiki_cms\/groupware
|
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newslet…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9305
|
2024-11-21 12:35 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|