|
247051
|
8.8 |
HIGH
Network
|
atmail
|
atmail
|
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
|
CWE-352
Origin Validation Error
|
CVE-2017-9519
|
2024-11-21 12:36 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247052
|
8.8 |
HIGH
Network
|
atmail
|
atmail
|
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
|
CWE-352
Origin Validation Error
|
CVE-2017-9518
|
2024-11-21 12:36 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247053
|
8.8 |
HIGH
Network
|
atmail
|
atmail
|
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
|
CWE-352
Origin Validation Error
|
CVE-2017-9517
|
2024-11-21 12:36 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247054
|
5.4 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9516
|
2024-11-21 12:36 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247055
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function LockSemaphoreInfo, which allows attackers to cause a denial of service via a crafted file.
|
CWE-617
Reachable Assertion
|
CVE-2017-9501
|
2024-11-21 12:36 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247056
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attackers to cause a denial of service via a crafted file.
|
CWE-617
Reachable Assertion
|
CVE-2017-9500
|
2024-11-21 12:36 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247057
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attackers to cause a denial of service via a crafted file.
|
CWE-617
Reachable Assertion
|
CVE-2017-9499
|
2024-11-21 12:36 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247058
|
5.5 |
MEDIUM
Local
|
ytnef_project
|
ytnef
|
In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9474
|
2024-11-21 12:36 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247059
|
5.5 |
MEDIUM
Local
|
ytnef_project canonical
|
ytnef ubuntu_linux
|
In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
|
NVD-CWE-noinfo
|
CVE-2017-9473
|
2024-11-21 12:36 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247060
|
5.5 |
MEDIUM
Local
|
ytnef_project
|
ytnef
|
In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9472
|
2024-11-21 12:36 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|