|
255171
|
7.5 |
HIGH
Network
|
libsass
|
libsass
|
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
|
CWE-674
Uncontrolled Recursion
|
CVE-2017-11554
|
2024-11-21 12:08 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255172
|
7.5 |
HIGH
Network
|
exiv2
|
exiv2
|
There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26. A crafted input will lead to remote denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2017-11553
|
2024-11-21 12:08 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255173
|
7.8 |
HIGH
Local
|
cyberark
|
viewfinity
|
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option.
|
NVD-CWE-noinfo
|
CVE-2017-11197
|
2024-11-21 12:07 |
2023-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255174
|
9.8 |
CRITICAL
Network
|
sensiolabs
|
symfony
|
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The compo…
|
CWE-284
Improper Access Control
|
CVE-2017-11365
|
2024-11-21 12:07 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255175
|
9.8 |
CRITICAL
Network
|
omniauth
|
omniauth_saml
|
OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data wit…
|
CWE-287
Improper Authentication
|
CVE-2017-11430
|
2024-11-21 12:07 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255176
|
9.8 |
CRITICAL
Network
|
clever
|
saml2-js
|
Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without inval…
|
CWE-287
Improper Authentication
|
CVE-2017-11429
|
2024-11-21 12:07 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255177
|
9.8 |
CRITICAL
Network
|
onelogin
|
ruby-saml
|
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without …
|
CWE-287
Improper Authentication
|
CVE-2017-11428
|
2024-11-21 12:07 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255178
|
9.8 |
CRITICAL
Network
|
onelogin
|
pythonsaml
|
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without…
|
CWE-287
Improper Authentication
|
CVE-2017-11427
|
2024-11-21 12:07 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255179
|
7.8 |
HIGH
Local
|
google
|
android
|
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the boot image header, an out of bounds read can occur in boot.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11078
|
2024-11-21 12:07 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255180
|
9.8 |
CRITICAL
Network
|
qualcomm
|
msm8909w_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_430_firmware sd_450_firmware sd_617_firmware sd_625_firmware sd_650_firmware sd_6…
|
Improper Input Validation in Linux io-prefetch in Snapdragon Mobile and Snapdragon Wear, A SQL injection vulnerability exists in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 430, SD 450, SD…
|
CWE-89
SQL Injection
|
CVE-2017-11088
|
2024-11-21 12:07 |
2018-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|