|
247791
|
3.7 |
LOW
Network
|
owncloud
|
owncloud
|
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is v…
|
CWE-200
Information Exposure
|
CVE-2017-5865
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247792
|
7.5 |
HIGH
Network
|
libimobiledevice
|
libplist
|
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an inv…
|
CWE-415
Double Free
|
CVE-2017-5836
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247793
|
7.5 |
HIGH
Network
|
libimobiledevice
|
libplist
|
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-5835
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247794
|
5.5 |
MEDIUM
Local
|
libimobiledevice
|
libplist
|
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5834
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247795
|
6.1 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via un…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5833
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247796
|
5.4 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5832
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247797
|
5.9 |
MEDIUM
Network
|
revive-adserver
|
revive_adserver
|
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.
|
CWE-384
Session Fixation
|
CVE-2017-5831
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247798
|
9.8 |
CRITICAL
Network
|
revive-adserver
|
revive_adserver
|
Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-5830
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247799
|
6.1 |
MEDIUM
Network
|
cpanel
|
cgiecho cgiemail
|
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5616
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247800
|
6.1 |
MEDIUM
Network
|
cpanel
|
cgiecho cgiemail
|
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
|
CWE-601
Open Redirect
|
CVE-2017-5615
|
2024-11-21 12:28 |
2017-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|