|
249251
|
2.7 |
LOW
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).
|
CWE-20
Improper Input Validation
|
CVE-2017-18393
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249252
|
2.0 |
LOW
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).
|
CWE-20
Improper Input Validation
|
CVE-2017-18392
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249253
|
2.5 |
LOW
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323).
|
CWE-200
Information Exposure
|
CVE-2017-18391
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249254
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322).
|
CWE-275
Permission Issues
|
CVE-2017-18390
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249255
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
|
CWE-74
Injection
|
CVE-2017-18389
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249256
|
8.8 |
HIGH
Network
|
atlassian
|
data_center jira
|
The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to ex…
|
CWE-94
Code Injection
|
CVE-2017-18113
|
2024-11-21 12:19 |
2021-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249257
|
6.5 |
MEDIUM
Network
|
atlassian
|
fisheye
|
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are b…
|
CWE-200
Information Exposure
|
CVE-2017-18112
|
2024-11-21 12:19 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249258
|
5.9 |
MEDIUM
Network
|
bitcoin
|
bitcoin_core
|
bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server re…
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-18350
|
2024-11-21 12:19 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249259
|
6.5 |
MEDIUM
Network
|
atlassian
|
crowd
|
Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) …
|
CWE-352
Origin Validation Error
|
CVE-2017-18107
|
2024-11-21 12:19 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249260
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
|
CWE-20
Improper Input Validation
|
CVE-2017-18388
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|