|
250991
|
5.4 |
MEDIUM
Network
|
logitech
|
media_server
|
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a "favorite."
|
CWE-79
Cross-site Scripting
|
CVE-2017-16567
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250992
|
9.8 |
CRITICAL
Network
|
userproplugin
|
userpro
|
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value f…
|
CWE-287
Improper Authentication
|
CVE-2017-16562
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250993
|
7.5 |
HIGH
Network
|
brother
|
dcp-j132w_firmware
|
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with …
|
NVD-CWE-noinfo
|
CVE-2017-16249
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250994
|
5.9 |
MEDIUM
Network
|
librenms
|
librenms
|
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.
|
CWE-22
Path Traversal
|
CVE-2017-16759
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250995
|
4.8 |
MEDIUM
Network
|
ultimate_instagram_feed_project
|
ultimate_instagram_feed
|
Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16758
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250996
|
7.8 |
HIGH
Local
|
hola
|
vpn
|
Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-16757
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250997
|
5.5 |
MEDIUM
Local
|
swftools
|
swftools
|
The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failure, which allows remote attackers to cause a denial of service (NULL pointer der…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-16711
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250998
|
8.0 |
HIGH
Adjacent
|
datto
|
windows_agent
|
Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command …
|
NVD-CWE-noinfo
|
CVE-2017-16674
|
2024-11-21 12:16 |
2017-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250999
|
5.3 |
MEDIUM
Adjacent
|
datto
|
backup_agent
|
Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to "pair" with the agent and issue requests to this …
|
CWE-200
Information Exposure
|
CVE-2017-16673
|
2024-11-21 12:16 |
2017-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251000
|
5.9 |
MEDIUM
Network
|
digium
|
asterisk certified_asterisk
|
An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-16672
|
2024-11-21 12:16 |
2017-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|