|
251931
|
7.5 |
HIGH
Network
|
salesforce
|
tough-cookie
|
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie ma…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-15010
|
2024-11-21 12:13 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251932
|
6.1 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
PRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page), via the errormsg parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15009
|
2024-11-21 12:13 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251933
|
4.8 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error handling for a %00 in the SRC attribute of an IMG element.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15008
|
2024-11-21 12:13 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251934
|
6.5 |
MEDIUM
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2017-14997
|
2024-11-21 12:13 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251935
|
6.5 |
MEDIUM
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonN…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14994
|
2024-11-21 12:13 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251936
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive information from uninitialized kernel heap-memory locations via an SG_GET_REQUEST_T…
|
CWE-200
Information Exposure
|
CVE-2017-14991
|
2024-11-21 12:13 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251937
|
6.1 |
MEDIUM
Network
|
wso2
|
machine_learner data_services_server dashboard_server complex_event_processor business_rules_server business_process_server application_server data_analytics_server
|
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Da…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14995
|
2024-11-21 12:13 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251938
|
6.5 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack u…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2017-14990
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251939
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the application via a crafted font file, because the FT_Done_Glyph function (from Free…
|
CWE-416
Use After Free
|
CVE-2017-14989
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251940
|
5.5 |
MEDIUM
Local
|
openexr
|
openexr
|
Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file that is accessed with the ImfOpenInputF…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-14988
|
2024-11-21 12:13 |
2017-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|