|
250011
|
7.5 |
HIGH
Network
|
blogotext_project
|
blogotext
|
Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read…
|
CWE-200
Information Exposure
|
CVE-2017-17793
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250012
|
6.1 |
MEDIUM
Network
|
blogotext_project
|
blogotext
|
Cross site scripting (XSS) vulnerability in the markup_clean_href function in inc/conv.php in BlogoText through 3.7.6 allows remote attackers to inject arbitrary JavaScript via a comment.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17792
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250013
|
9.8 |
CRITICAL
Network
|
ruby-lang
|
ruby
|
The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|…
|
CWE-74
Injection
|
CVE-2017-17790
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250014
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-17789
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250015
|
5.5 |
MEDIUM
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17788
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250016
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17787
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250017
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17786
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250018
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-17785
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250019
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17784
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250020
|
7.5 |
HIGH
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17783
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|