|
247111
|
8.8 |
HIGH
Network
|
sap
|
netweaver_application_server_java
|
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/se…
|
CWE-611
XXE
|
CVE-2017-8913
|
2024-11-21 12:34 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247112
|
4.6 |
MEDIUM
Physics
|
whatsapp
|
whatsapp
|
Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-8769
|
2024-11-21 12:34 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247113
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2017-8917
|
2024-11-21 12:34 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247114
|
7.8 |
HIGH
Local
|
smb4k_project debian
|
smb4k debian_linux
|
smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.
|
CWE-20
Improper Input Validation
|
CVE-2017-8849
|
2024-11-21 12:34 |
2017-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247115
|
7.8 |
HIGH
Local
|
kde
|
kauth kdelibs
|
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2017-8422
|
2024-11-21 12:34 |
2017-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247116
|
7.8 |
HIGH
Local
|
cgmlarson
|
vizex_reader
|
Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8927
|
2024-11-21 12:34 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247117
|
7.8 |
HIGH
Local
|
halliburton
|
logview_pro
|
Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8926
|
2024-11-21 12:34 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247118
|
8.8 |
HIGH
Network
|
mailcow
|
mailcow\
|
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2017-8928
|
2024-11-21 12:34 |
2017-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247119
|
5.5 |
MEDIUM
Local
|
linux debian
|
linux_kernel debian_linux
|
The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2017-8925
|
2024-11-21 12:34 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247120
|
4.6 |
MEDIUM
Physics
|
linux debian
|
linux_kernel debian_linux
|
The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uniniti…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2017-8924
|
2024-11-21 12:34 |
2017-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|