|
249841
|
7.8 |
HIGH
Local
|
ikarussecurity
|
anti.virus
|
In IKARUS anti.virus 2.16.20, the driver file (ntguard.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values fro…
|
CWE-20
Improper Input Validation
|
CVE-2017-17795
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249842
|
9.8 |
CRITICAL
Network
|
blogotext_project
|
blogotext
|
validate_form_preferences in admin/preferences.php in BlogoText through 3.7.6 allows attackers to bypass intended access restrictions via vectors related to an e-mail address field.
|
NVD-CWE-noinfo
|
CVE-2017-17794
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249843
|
7.5 |
HIGH
Network
|
blogotext_project
|
blogotext
|
Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read…
|
CWE-200
Information Exposure
|
CVE-2017-17793
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249844
|
6.1 |
MEDIUM
Network
|
blogotext_project
|
blogotext
|
Cross site scripting (XSS) vulnerability in the markup_clean_href function in inc/conv.php in BlogoText through 3.7.6 allows remote attackers to inject arbitrary JavaScript via a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17792
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249845
|
9.8 |
CRITICAL
Network
|
ruby-lang
|
ruby
|
The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|…
|
CWE-74
Injection
|
CVE-2017-17790
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249846
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-17789
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249847
|
5.5 |
MEDIUM
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17788
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249848
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17787
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249849
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17786
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249850
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-17785
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|