|
255391
|
5.5 |
MEDIUM
Local
|
freedesktop
|
poppler
|
In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14517
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255392
|
7.5 |
HIGH
Network
|
tenda
|
w15e_firmware
|
Heap-based Buffer Overflow on Tenda W15E devices before 15.11.0.14 allows remote attackers to cause a denial of service (temporary HTTP outage and forced logout) via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14515
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255393
|
7.5 |
HIGH
Network
|
tenda
|
w15e_firmware
|
Directory Traversal on Tenda W15E devices before 15.11.0.14 allows remote attackers to read unencrypted files via a crafted URL.
|
CWE-22
Path Traversal
|
CVE-2017-14514
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255394
|
5.3 |
MEDIUM
Network
|
metinfo
|
metinfo
|
Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the f_filename parameter in a fingerprintdo action to admin/app/physical/p…
|
CWE-22
Path Traversal
|
CVE-2017-14513
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255395
|
9.8 |
CRITICAL
Network
|
nexusphp_project
|
nexusphp
|
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.
|
CWE-89
SQL Injection
|
CVE-2017-14512
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255396
|
7.5 |
HIGH
Network
|
sap
|
e-recruiting
|
An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/she receives a link by email to confirm access to …
|
CWE-20
Improper Input Validation
|
CVE-2017-14511
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255397
|
6.1 |
MEDIUM
Network
|
sugarcrm
|
sugarcrm
|
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLeadCapture functionality is found vulnerable to unau…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14510
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255398
|
8.8 |
HIGH
Network
|
sugarcrm
|
sugarcrm
|
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote file inclusion has been identified in the Connectors …
|
CWE-20
Improper Input Validation
|
CVE-2017-14509
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255399
|
8.8 |
HIGH
Network
|
sugarcrm
|
sugarcrm
|
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several areas have been identified in the Documents and Emails…
|
CWE-89
SQL Injection
|
CVE-2017-14508
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255400
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
DrawGetStrokeDashArray in wand/drawing-wand.c in ImageMagick 7.0.7-1 mishandles certain NULL arrays, which allows attackers to perform Denial of Service (NULL pointer dereference and application cras…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14505
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|