|
246861
|
5.9 |
MEDIUM
Network
|
gnupg
|
libgcrypt
|
In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ec…
|
CWE-200
Information Exposure
|
CVE-2017-9526
|
2024-11-21 12:36 |
2017-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246862
|
6.7 |
MEDIUM
Local
|
cron_project debian
|
cron debian_linux
|
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks aga…
|
CWE-59
Link Following
|
CVE-2017-9525
|
2024-11-21 12:36 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246863
|
6.1 |
MEDIUM
Network
|
sophos
|
web_appliance
|
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9523
|
2024-11-21 12:36 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246864
|
5.5 |
MEDIUM
Local
|
radare
|
radare2
|
The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.
|
CWE-416
Use After Free
|
CVE-2017-9520
|
2024-11-21 12:36 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246865
|
8.8 |
HIGH
Network
|
atmail
|
atmail
|
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.
|
CWE-352
Origin Validation Error
|
CVE-2017-9519
|
2024-11-21 12:36 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246866
|
8.8 |
HIGH
Network
|
atmail
|
atmail
|
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.
|
CWE-352
Origin Validation Error
|
CVE-2017-9518
|
2024-11-21 12:36 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246867
|
8.8 |
HIGH
Network
|
atmail
|
atmail
|
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.
|
CWE-352
Origin Validation Error
|
CVE-2017-9517
|
2024-11-21 12:36 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246868
|
5.4 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9516
|
2024-11-21 12:36 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246869
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function LockSemaphoreInfo, which allows attackers to cause a denial of service via a crafted file.
|
CWE-617
Reachable Assertion
|
CVE-2017-9501
|
2024-11-21 12:36 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246870
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attackers to cause a denial of service via a crafted file.
|
CWE-617
Reachable Assertion
|
CVE-2017-9500
|
2024-11-21 12:36 |
2017-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|