|
250371
|
6.5 |
MEDIUM
Network
|
tp-link
|
tl-wvr300_firmware tl-wvr302_firmware tl-wvr450_firmware tl-wvr450l_firmware tl-wvr450g_firmware tl-wvr458_firmware tl-wvr458l_firmware tl-wvr458p_firmware tl-wvr900g_firmware…
|
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;local…
|
CWE-22
Path Traversal
|
CVE-2017-16959
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250372
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wvr300_firmware tl-wvr302_firmware tl-wvr450_firmware tl-wvr450l_firmware tl-wvr450g_firmware tl-wvr458_firmware tl-wvr458l_firmware tl-wvr458p_firmware tl-wvr900g_firmware…
|
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luc…
|
CWE-78
OS Command
|
CVE-2017-16958
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250373
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wvr300_firmware tl-wvr302_firmware tl-wvr450_firmware tl-wvr450l_firmware tl-wvr450g_firmware tl-wvr458_firmware tl-wvr458l_firmware tl-wvr458p_firmware tl-wvr900g_firmware…
|
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/lu…
|
CWE-78
OS Command
|
CVE-2017-16957
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250374
|
7.8 |
HIGH
Local
|
tgsoft
|
vir.it_explorer
|
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730008 DeviceIoContr…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-16948
|
2024-11-21 12:17 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250375
|
4.9 |
MEDIUM
Network
|
misp
|
misp
|
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-16946
|
2024-11-21 12:17 |
2017-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250376
|
7.5 |
HIGH
Network
|
exim debian
|
exim debian_linux
|
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT com…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-16944
|
2024-11-21 12:17 |
2017-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250377
|
9.8 |
CRITICAL
Network
|
exim debian
|
exim debian_linux
|
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BD…
|
CWE-416
Use After Free
|
CVE-2017-16943
|
2024-11-21 12:17 |
2017-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250378
|
6.5 |
MEDIUM
Network
|
libsndfile_project
|
libsndfile
|
In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the function wav_w64_read_fmt_chunk() in wav_w64.c, which may lead to DoS when playing a crafted audio file.
|
CWE-369
Divide By Zero
|
CVE-2017-16942
|
2024-11-21 12:17 |
2017-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250379
|
8.8 |
HIGH
Network
|
octobercms
|
october
|
October CMS through 1.0.428 does not prevent use of .htaccess in themes, which allows remote authenticated users to execute arbitrary PHP code by downloading a theme ZIP archive from /backend/cms/the…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-16941
|
2024-11-21 12:17 |
2017-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250380
|
7.8 |
HIGH
Local
|
linux debian
|
linux_kernel debian_linux
|
The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCV…
|
CWE-416
Use After Free
|
CVE-2017-16939
|
2024-11-21 12:17 |
2017-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|