|
248091
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key sy…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6951
|
2024-11-21 12:30 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248092
|
8.1 |
HIGH
Network
|
call-cc
|
chicken
|
An issue was discovered in CHICKEN Scheme through 4.12.0. When using a nonstandard CHICKEN-specific extension to allocate an SRFI-4 vector in unmanaged memory, the vector size would be used in unsani…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6949
|
2024-11-21 12:30 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248093
|
4.3 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Social can be changed.
|
CWE-352
Origin Validation Error
|
CVE-2017-6918
|
2024-11-21 12:30 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248094
|
4.3 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
CSRF exists in BigTree CMS 4.2.16 with the value parameter to the admin/settings/update/ page. The Colophon can be changed.
|
CWE-352
Origin Validation Error
|
CVE-2017-6917
|
2024-11-21 12:30 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248095
|
4.3 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page. The Navigation Social can be changed.
|
CWE-352
Origin Validation Error
|
CVE-2017-6916
|
2024-11-21 12:30 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248096
|
4.3 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
CSRF exists in BigTree CMS 4.1.18 with the colophon parameter to the admin/settings/update/ page. The Colophon can be changed.
|
CWE-352
Origin Validation Error
|
CVE-2017-6915
|
2024-11-21 12:30 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248097
|
7.1 |
HIGH
Network
|
bigtreecms
|
bigtree_cms
|
CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page. A user can be deleted.
|
CWE-352
Origin Validation Error
|
CVE-2017-6914
|
2024-11-21 12:30 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248098
|
7.8 |
HIGH
Local
|
jasper_project
|
jasper
|
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote attackers to have unspecified impact via a crafted image.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6852
|
2024-11-21 12:30 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248099
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-6851
|
2024-11-21 12:30 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248100
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6850
|
2024-11-21 12:30 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|