|
251851
|
5.4 |
MEDIUM
Network
|
octobercms
|
october
|
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened …
|
CWE-79
Cross-site Scripting
|
CVE-2017-15284
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251852
|
8.8 |
HIGH
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to "…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15281
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251853
|
5.5 |
MEDIUM
Local
|
umbraco
|
umbraco_cms
|
XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF…
|
CWE-611
XXE
|
CVE-2017-15280
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251854
|
5.4 |
MEDIUM
Network
|
umbraco
|
umbraco_cms
|
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15279
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251855
|
5.4 |
MEDIUM
Network
|
teampass
|
teampass
|
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arb…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15278
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251856
|
6.5 |
MEDIUM
Network
|
imagemagick graphicsmagick
|
imagemagick graphicsmagick
|
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected …
|
CWE-200
Information Exposure
|
CVE-2017-15277
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251857
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
security/keys/keyctl.c in the Linux kernel before 4.11.5 does not consider the case of a NULL payload in conjunction with a nonzero length value, which allows local users to cause a denial of service…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15274
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251858
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview
|
IrfanView version 4.44 (32bit) allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file, related to "Data from Faulting Address is used as one o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15264
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251859
|
8.8 |
HIGH
Network
|
qualiteam
|
x-cart
|
X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check remote file extensions before saving locally. This…
|
CWE-20
Improper Input Validation
|
CVE-2017-15285
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251860
|
7.8 |
HIGH
Local
|
irfanview
|
pdf irfanview
|
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faul…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15263
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|