|
253591
|
5.9 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-17716
|
2024-11-21 12:18 |
2017-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253592
|
6.1 |
MEDIUM
Network
|
boxug
|
trape
|
Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /regi…
|
CWE-79
Cross-site Scripting
|
CVE-2017-17714
|
2024-11-21 12:18 |
2017-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253593
|
9.8 |
CRITICAL
Network
|
boxug
|
trape
|
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter,…
|
CWE-89
SQL Injection
|
CVE-2017-17713
|
2024-11-21 12:18 |
2017-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253594
|
8.8 |
HIGH
Network
|
telegram
|
telegram_messenger
|
The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal via a pathname obtained in a file-transfer request from a re…
|
CWE-22
Path Traversal
|
CVE-2017-17715
|
2024-11-21 12:18 |
2017-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253595
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
The raw_sendmsg() function in net/ipv4/raw.c in the Linux kernel through 4.14.6 has a race condition in inet->hdrincl that leads to uninitialized stack pointer usage; this allows a local user to exec…
|
CWE-362
Race Condition
|
CVE-2017-17712
|
2024-11-21 12:18 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253596
|
9.8 |
CRITICAL
Network
|
k7computing
|
antivirus
|
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-17701
|
2024-11-21 12:18 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253597
|
9.8 |
CRITICAL
Network
|
k7computing
|
antivirus
|
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025a4 DeviceIoControl request.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-17700
|
2024-11-21 12:18 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253598
|
9.8 |
CRITICAL
Network
|
k7computing
|
antivirus
|
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-17699
|
2024-11-21 12:18 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253599
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_password_manager_pro
|
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17698
|
2024-11-21 12:18 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253600
|
5.1 |
MEDIUM
Local
|
hp
|
synaptics_touchpad_driver
|
A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by modifying registry keys.
|
CWE-200
Information Exposure
|
CVE-2017-17556
|
2024-11-21 12:18 |
2017-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|