|
254251
|
8.8 |
HIGH
Network
|
libtiff
|
libtiff
|
In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue
|
CWE-416
Use After Free
|
CVE-2017-17973
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254252
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17971
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254253
|
6.1 |
MEDIUM
Network
|
netwin
|
surgeftp
|
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17933
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254254
|
9.8 |
CRITICAL
Network
|
xi-soft
|
nettransport_download_manager
|
A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP respons…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17968
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254255
|
5.5 |
MEDIUM
Local
|
ksosoft
|
wps_office
|
pptreader.dll in Kingsoft WPS Office 10.1.0.6930 allows remote attackers to cause a denial of service via a crafted PPT file, aka CNVD-2017-35482.
|
CWE-20
Improper Input Validation
|
CVE-2017-17967
|
2024-11-21 12:19 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254256
|
8.8 |
HIGH
Network
|
php_multivendor_ecommerce_project
|
php_multivendor_ecommerce
|
PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.
|
CWE-352
Origin Validation Error
|
CVE-2017-17960
|
2024-11-21 12:19 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254257
|
9.8 |
CRITICAL
Network
|
php_multivendor_ecommerce_project
|
php_multivendor_ecommerce
|
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17959
|
2024-11-21 12:19 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254258
|
6.1 |
MEDIUM
Network
|
php_multivendor_ecommerce_project
|
php_multivendor_ecommerce
|
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17958
|
2024-11-21 12:19 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254259
|
9.8 |
CRITICAL
Network
|
php_multivendor_ecommerce_project
|
php_multivendor_ecommerce
|
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17957
|
2024-11-21 12:19 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254260
|
6.1 |
MEDIUM
Network
|
php_multivendor_ecommerce_project
|
php_multivendor_ecommerce
|
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17956
|
2024-11-21 12:19 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|