|
251591
|
6.1 |
MEDIUM
Network
|
softwarepublico
|
e-sic
|
XSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the requester's registration area) via the nome parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15380
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251592
|
9.8 |
CRITICAL
Network
|
softwarepublico
|
e-sic
|
An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
|
CWE-89
SQL Injection
|
CVE-2017-15379
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251593
|
8.8 |
HIGH
Network
|
softwarepublico
|
e-sic
|
SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
|
CWE-89
SQL Injection
|
CVE-2017-15378
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251594
|
7.5 |
HIGH
Network
|
openinfosecfoundation
|
suricata
|
In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspection in detect-engi…
|
NVD-CWE-noinfo
|
CVE-2017-15377
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251595
|
7.5 |
HIGH
Network
|
irssi
|
irssi
|
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-15228
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251596
|
7.5 |
HIGH
Network
|
irssi
|
irssi
|
Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the stat…
|
CWE-416
Use After Free
|
CVE-2017-15227
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251597
|
5.9 |
MEDIUM
Network
|
gnu
|
glibc
|
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user na…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-15671
|
2024-11-21 12:14 |
2017-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251598
|
9.8 |
CRITICAL
Network
|
gnu
|
glibc
|
The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.c, related to the processing of home directories u…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15670
|
2024-11-21 12:14 |
2017-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251599
|
6.1 |
MEDIUM
Network
|
tp-link
|
tl-mr3220_firmware
|
Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description fi…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15291
|
2024-11-21 12:14 |
2017-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251600
|
6.7 |
MEDIUM
Local
|
paessler
|
prtg_network_monitor
|
PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of the error message.
|
CWE-20
Improper Input Validation
|
CVE-2017-15651
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|