|
250971
|
5.5 |
MEDIUM
Local
|
swftools
|
swftools
|
The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows remote attackers to cause a denial of service (heap-b…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-16794
|
2024-11-21 12:16 |
2017-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250972
|
7.8 |
HIGH
Local
|
swftools
|
swftools
|
The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote attackers to cause a denial of service (incorrect malloc and heap-based buffer ov…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16793
|
2024-11-21 12:16 |
2017-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250973
|
7.5 |
HIGH
Network
|
inedo
|
buildmaster
|
Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.
|
CWE-269
Improper Privilege Management
|
CVE-2017-16520
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250974
|
6.1 |
MEDIUM
Network
|
cacti
|
cacti
|
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16785
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250975
|
6.1 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16784
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250976
|
9.8 |
CRITICAL
Network
|
cmsmadesimple
|
cms_made_simple
|
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
|
CWE-94
Code Injection
|
CVE-2017-16783
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250977
|
6.1 |
MEDIUM
Network
|
home-assistant
|
home-assistant
|
In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16782
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250978
|
5.4 |
MEDIUM
Network
|
mybb
|
mybb
|
The installer in MyBB before 1.8.13 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16781
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250979
|
9.8 |
CRITICAL
Network
|
mybb
|
mybb
|
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
|
CWE-352
Origin Validation Error
|
CVE-2017-16780
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250980
|
6.1 |
MEDIUM
Network
|
dlink
|
dwr-933_firmware
|
XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16765
|
2024-11-21 12:16 |
2017-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|