|
247851
|
8.8 |
HIGH
Network
|
ntop
|
ntopng
|
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user…
|
CWE-352
Origin Validation Error
|
CVE-2017-5473
|
2024-11-21 12:27 |
2017-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247852
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_pdf_toolkit
|
Memory Corruption Vulnerability in Foxit PDF Toolkit v1.3 allows an attacker to cause Denial of Service and Remote Code Execution when the victim opens the specially crafted PDF file. The Vulnerabili…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5364
|
2024-11-21 12:27 |
2017-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247853
|
9.8 |
CRITICAL
Network
|
libtiff
|
libtiff
|
LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5225
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247854
|
7.5 |
HIGH
Network
|
samsung
|
samsung_mobile
|
Samsung Note devices with KK(4.4), L(5.0/5.1), and M(6.0) software allow attackers to crash the system by creating an arbitrarily large number of active VR service threads. The Samsung ID is SVE-2016…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-5351
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247855
|
7.5 |
HIGH
Network
|
samsung
|
samsung_mobile
|
Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allow attackers to crash systemUI by leveraging incomplete exception handling. The Samsung ID is SVE-2016-7122.
|
NVD-CWE-noinfo
|
CVE-2017-5350
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247856
|
7.2 |
HIGH
Network
|
metalgenix
|
genixcms
|
SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/ind…
|
CWE-89
SQL Injection
|
CVE-2017-5347
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247857
|
7.2 |
HIGH
Network
|
genixcms
|
genixcms
|
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin…
|
CWE-89
SQL Injection
|
CVE-2017-5346
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247858
|
8.8 |
HIGH
Network
|
metalgenix
|
genixcms
|
SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default…
|
CWE-89
SQL Injection
|
CVE-2017-5345
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247859
|
9.1 |
CRITICAL
Network
|
libimobiledevice
|
libplist
|
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) vi…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5209
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247860
|
9.8 |
CRITICAL
Network
|
php netapp
|
php clustered_data_ontap
|
Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial o…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5340
|
2024-11-21 12:27 |
2017-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|