|
251841
|
5.5 |
MEDIUM
Local
|
git-scm canonical
|
git ubuntu_linux
|
Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an i…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-15298
|
2024-11-21 12:14 |
2017-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251842
|
5.9 |
MEDIUM
Network
|
infineon
|
trusted_platform_firmware rsa_library
|
The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 13…
|
NVD-CWE-noinfo
|
CVE-2017-15361
|
2024-11-21 12:14 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251843
|
6.1 |
MEDIUM
Network
|
wpjobboard
|
wpjobboard
|
Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query` and `id` paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15375
|
2024-11-21 12:14 |
2017-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251844
|
6.1 |
MEDIUM
Network
|
shopware
|
shopware
|
Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject malicious script c…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15374
|
2024-11-21 12:14 |
2017-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251845
|
7.8 |
HIGH
Local
|
cpuid
|
cpu-z
|
In CPUID CPU-Z through 1.81, there are improper access rights to a kernel-mode driver (e.g., cpuz143_x64.sys for version 1.43) that can result in information disclosure or elevation of privileges, be…
|
NVD-CWE-noinfo
|
CVE-2017-15302
|
2024-11-21 12:14 |
2017-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251846
|
7.5 |
HIGH
Network
|
mirasys
|
video_management_system
|
Mirasys Video Management System (VMS) 6.x before 6.4.6, 7.x before 7.5.15, and 8.x before 8.1.1 has a login process in which cleartext data is sent from a server to a client, and not all of this data…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2017-15290
|
2024-11-21 12:14 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251847
|
6.1 |
MEDIUM
Network
|
bouqueteditor_project
|
bouqueteditor
|
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15287
|
2024-11-21 12:14 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251848
|
7.5 |
HIGH
Network
|
qemu
|
qemu
|
Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-websock.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-15268
|
2024-11-21 12:14 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251849
|
8.8 |
HIGH
Network
|
opentext
|
documentum_content_server
|
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Ser…
|
CWE-22
Path Traversal
|
CVE-2017-15276
|
2024-11-21 12:14 |
2017-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251850
|
7.5 |
HIGH
Network
|
sqlite
|
sqlite
|
SQLite 3.20.1 has a NULL pointer dereference in tableColumnList in shell.c because it fails to consider certain cases where `sqlite3_step(pStmt)==SQLITE_ROW` is false and a data structure is never in…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15286
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|