|
255141
|
7.5 |
HIGH
Network
|
sam2p_project
|
sam2p
|
In sam2p 0.49.3, the in_xpm_reader function in in_xpm.cpp has an integer signedness error, leading to a crash when writing to an out-of-bounds array element.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-14629
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255142
|
9.8 |
CRITICAL
Network
|
sam2p_project
|
sam2p
|
In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14628
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255143
|
9.8 |
CRITICAL
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_decode in coders/sixel.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14626
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255144
|
9.8 |
CRITICAL
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_create in coders/sixel.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14625
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255145
|
9.8 |
CRITICAL
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function PostscriptDelegateMessage in coders/ps.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14624
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255146
|
8.1 |
HIGH
Network
|
go-ldap_project
|
ldap
|
In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application using this package if these conditions are met: (…
|
CWE-287
Improper Authentication
|
CVE-2017-14623
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255147
|
5.4 |
MEDIUM
Network
|
suse
|
portus
|
Portus 2.2.0 has XSS via the Team field, related to typeahead.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14621
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255148
|
6.1 |
MEDIUM
Network
|
phpmyfaq
|
phpmyfaq
|
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configuration Module.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14619
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255149
|
4.8 |
MEDIUM
Network
|
phpmyfaq
|
phpmyfaq
|
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14618
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255150
|
7.8 |
HIGH
Local
|
freedesktop
|
poppler
|
In Poppler 0.59.0, a floating point exception occurs in the ImageStream class in Stream.cc, which may lead to a potential attack when handling malicious PDF files.
|
CWE-20
Improper Input Validation
|
CVE-2017-14617
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|