|
250241
|
6.1 |
MEDIUM
Network
|
mistune_project fedoraproject
|
mistune fedora
|
Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape t…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16876
|
2024-11-21 12:17 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250242
|
7.8 |
HIGH
Local
|
sony
|
content_manager_assistant
|
Untrusted search path vulnerability in Content Manager Assistant for PlayStation version 3.55.7671.0901 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified dire…
|
CWE-426
Untrusted Search Path
|
CVE-2017-17010
|
2024-11-21 12:17 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250243
|
7.8 |
HIGH
Local
|
linux debian
|
linux_kernel debian_linux
|
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging register truncatio…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16996
|
2024-11-21 12:17 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250244
|
7.8 |
HIGH
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by lev…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16995
|
2024-11-21 12:17 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250245
|
8.1 |
HIGH
Network
|
auth0
|
passport-wsfed-saml2
|
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate the…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2017-16897
|
2024-11-21 12:17 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250246
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17033
|
2024-11-21 12:17 |
2017-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250247
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17032
|
2024-11-21 12:17 |
2017-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250248
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17031
|
2024-11-21 12:17 |
2017-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250249
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to e…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17030
|
2024-11-21 12:17 |
2017-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250250
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to e…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17029
|
2024-11-21 12:17 |
2017-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|