|
252761
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a LayerStack can be destroyed in between Validate and Commit by the application resulti…
|
CWE-416
Use After Free
|
CVE-2017-15849
|
2024-11-21 12:15 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252762
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is conf…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15941
|
2024-11-21 12:15 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252763
|
6.1 |
MEDIUM
Network
|
apache
|
sling_xss_protection_api sling_xss_protection_api_compat
|
A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as …
|
CWE-79
Cross-site Scripting
|
CVE-2017-15717
|
2024-11-21 12:15 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252764
|
9.8 |
CRITICAL
Network
|
progress
|
sitefinity
|
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via ve…
|
CWE-287
Improper Authentication
|
CVE-2017-15883
|
2024-11-21 12:15 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252765
|
7.8 |
HIGH
Local
|
navercorp
|
whale
|
The Installer in Whale allows DLL hijacking.
|
CWE-426
Untrusted Search Path
|
CVE-2017-15913
|
2024-11-21 12:15 |
2018-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252766
|
9.8 |
CRITICAL
Network
|
apache
|
ofbiz
|
The BIRT plugin in Apache OFBiz 16.11.01 to 16.11.03 does not escape user input property passed. This allows for code injection by passing that code through the URL. For example by appending this cod…
|
CWE-74
Injection
|
CVE-2017-15714
|
2024-11-21 12:15 |
2018-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252767
|
5.4 |
MEDIUM
Network
|
synology
|
chat
|
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15892
|
2024-11-21 12:15 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252768
|
6.5 |
MEDIUM
Network
|
synology
|
chat
|
Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-15886
|
2024-11-21 12:15 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252769
|
9.8 |
CRITICAL
Network
|
sistemagpweb
|
gpweb
|
Insecure Permissions vulnerability in db.php file in GPWeb 8.4.61 allows remote attackers to view the password and user database.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-15877
|
2024-11-21 12:15 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252770
|
7.2 |
HIGH
Network
|
sistemagpweb
|
gpweb
|
Unrestricted File Upload vulnerability in GPWeb 8.4.61 allows remote authenticated users to upload any type of file, including a PHP shell.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15876
|
2024-11-21 12:15 |
2017-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|