|
250301
|
7.8 |
HIGH
Local
|
amazon
|
audible
|
ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched from a directory where an attacker has already creat…
|
CWE-426
Untrusted Search Path
|
CVE-2017-17069
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250302
|
9.8 |
CRITICAL
Network
|
samba debian
|
rsync debian_linux
|
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also …
|
NVD-CWE-noinfo
|
CVE-2017-17434
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250303
|
3.7 |
LOW
Network
|
debian samba
|
debian_linux rsync
|
The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_f…
|
CWE-862
Missing Authorization
|
CVE-2017-17433
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250304
|
7.5 |
HIGH
Network
|
openafs debian
|
openafs debian_linux
|
OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crash or application crash) via crafted fields, as demonstrated…
|
CWE-617
Reachable Assertion
|
CVE-2017-17432
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250305
|
6.1 |
MEDIUM
Network
|
genixcms
|
genixcms
|
GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17431
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250306
|
8.6 |
HIGH
Network
|
openstack
|
nova
|
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hyper…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-17051
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250307
|
8.1 |
HIGH
Network
|
gnu
|
glibc
|
The malloc function in the GNU C Library (aka glibc or libc6) 2.26 could return a memory block that is too small if an attempt is made to allocate an object whose size is close to SIZE_MAX, potential…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-17426
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250308
|
8.5 |
HIGH
Network
|
atlassian
|
bitbucket_auto_unapprove_plugin
|
It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsus…
|
CWE-362
Race Condition
|
CVE-2017-16857
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250309
|
6.1 |
MEDIUM
Network
|
atlassian
|
confluence
|
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16856
|
2024-11-21 12:17 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250310
|
7.5 |
HIGH
Network
|
i2pd getkovri
|
i2pd kovri
|
The (1) i2pd before 2.17 and (2) kovri pre-alpha implementations of the I2P routing protocol do not properly handle Garlic DeliveryTypeTunnel packets, which allows remote attackers to obtain sensitiv…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17066
|
2024-11-21 12:17 |
2017-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|