|
250471
|
3.7 |
LOW
Network
|
debian samba
|
debian_linux rsync
|
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_f…
|
CWE-862
Missing Authorization
|
CVE-2017-17433
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250472
|
7.5 |
HIGH
Network
|
openafs debian
|
openafs debian_linux
|
OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crash or application crash) via crafted fields, as demonstrated…
|
CWE-617
Reachable Assertion
|
CVE-2017-17432
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250473
|
6.1 |
MEDIUM
Network
|
genixcms
|
genixcms
|
GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17431
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250474
|
8.6 |
HIGH
Network
|
openstack
|
nova
|
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hyper…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-17051
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250475
|
8.1 |
HIGH
Network
|
gnu
|
glibc
|
The malloc function in the GNU C Library (aka glibc or libc6) 2.26 could return a memory block that is too small if an attempt is made to allocate an object whose size is close to SIZE_MAX, potential…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-17426
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250476
|
8.5 |
HIGH
Network
|
atlassian
|
bitbucket_auto_unapprove_plugin
|
It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsus…
|
CWE-362
Race Condition
|
CVE-2017-16857
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250477
|
6.1 |
MEDIUM
Network
|
atlassian
|
confluence
|
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16856
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250478
|
7.5 |
HIGH
Network
|
i2pd getkovri
|
i2pd kovri
|
The (1) i2pd before 2.17 and (2) kovri pre-alpha implementations of the I2P routing protocol do not properly handle Garlic DeliveryTypeTunnel packets, which allows remote attackers to obtain sensitiv…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17066
|
2024-11-21 12:17 |
2017-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250479
|
9.8 |
CRITICAL
Network
|
claymore_dual_miner_project
|
claymore_dual_miner
|
The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler. Th…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16930
|
2024-11-21 12:17 |
2017-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250480
|
8.1 |
HIGH
Network
|
claymore_dual_miner_project
|
claymore_dual_miner
|
The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a re…
|
CWE-119 CWE-22
Incorrect Access of Indexable Resource ('Range Error') Path Traversal
|
CVE-2017-16929
|
2024-11-21 12:17 |
2017-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|