|
248221
|
5.3 |
MEDIUM
Network
|
genixcms
|
genixcms
|
GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.
|
NVD-CWE-noinfo
|
CVE-2017-8388
|
2024-11-21 12:33 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248222
|
8.8 |
HIGH
Network
|
genixcms
|
genixcms
|
GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-8377
|
2024-11-21 12:33 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248223
|
5.4 |
MEDIUM
Network
|
genixcms
|
genixcms
|
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8376
|
2024-11-21 12:33 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248224
|
5.3 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2017-8385
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248225
|
6.1 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of …
|
CWE-79
Cross-site Scripting
|
CVE-2017-8384
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248226
|
5.3 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
|
NVD-CWE-noinfo
|
CVE-2017-8383
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248227
|
9.8 |
CRITICAL
Network
|
podofo_project
|
podofo
|
Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspe…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8378
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248228
|
5.5 |
MEDIUM
Local
|
underbit
|
mad_libmad
|
The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-8374
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248229
|
7.8 |
HIGH
Local
|
underbit
|
mad_libmad
|
The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecif…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8373
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248230
|
4.7 |
MEDIUM
Local
|
underbit
|
mad_libmad
|
The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b, if NDEBUG is omitted, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafte…
|
CWE-617
Reachable Assertion
|
CVE-2017-8372
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|