|
247821
|
7.5 |
HIGH
Network
|
kodi
|
kodi
|
Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by …
|
CWE-22
Path Traversal
|
CVE-2017-5982
|
2024-11-21 12:28 |
2017-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247822
|
9.8 |
CRITICAL
Network
|
fedoraproject gnome
|
fedora gtk-vnc
|
Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly e…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5885
|
2024-11-21 12:28 |
2017-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247823
|
7.8 |
HIGH
Local
|
fedoraproject gnome
|
fedora gtk-vnc
|
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) …
|
CWE-118
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5884
|
2024-11-21 12:28 |
2017-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247824
|
9.8 |
CRITICAL
Network
|
rubyzip_project debian
|
rubyzip debian_linux
|
The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "…
|
CWE-22
Path Traversal
|
CVE-2017-5946
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247825
|
3.7 |
LOW
Network
|
w3
|
high_resolution_time_api
|
The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now "Time to Tick" approach even with the http…
|
NVD-CWE-noinfo
|
CVE-2017-5928
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247826
|
7.5 |
HIGH
Network
|
intel amd samsung nvidia allwinner
|
core_i7-2620qm core_i7-6700k core_i5_m480 fx-8120_8-core e-350 atom_c2750 athlon_ii_640_x4 exynos_5800 celeron_n2840 fx-8320_8-core xeon_e5-2658_v2 tegra_k1_cd580m-a1…
|
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU ope…
|
CWE-200
Information Exposure
|
CVE-2017-5927
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247827
|
7.5 |
HIGH
Network
|
intel amd samsung nvidia allwinner
|
core_i7-2620qm core_i7-6700k core_i5_m480 fx-8120_8-core e-350 atom_c2750 athlon_ii_640_x4 exynos_5800 celeron_n2840 fx-8320_8-core xeon_e5-2658_v2 tegra_k1_cd580m-a1…
|
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU ope…
|
CWE-200
Information Exposure
|
CVE-2017-5926
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247828
|
7.5 |
HIGH
Network
|
intel amd samsung nvidia allwinner
|
core_i7-2620qm core_i7-6700k core_i5_m480 fx-8120_8-core e-350 atom_c2750 athlon_ii_640_x4 exynos_5800 celeron_n2840 fx-8320_8-core xeon_e5-2658_v2 tegra_k1_cd580m-a1…
|
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU o…
|
CWE-200
Information Exposure
|
CVE-2017-5925
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247829
|
7.8 |
HIGH
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and conseque…
|
NVD-CWE-noinfo
|
CVE-2017-5669
|
2024-11-21 12:28 |
2017-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247830
|
9.8 |
CRITICAL
Network
|
metalgenix
|
genixcms
|
CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.
|
CWE-352
Origin Validation Error
|
CVE-2017-5959
|
2024-11-21 12:28 |
2017-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|