|
249651
|
6.5 |
MEDIUM
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-18229
|
2024-11-21 12:19 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249652
|
5.4 |
MEDIUM
Network
|
bmc
|
remedy_action_request_system
|
Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18228
|
2024-11-21 12:19 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249653
|
7.5 |
HIGH
Network
|
titanhq
|
webtitan_gateway
|
TitanHQ WebTitan Gateway has incorrect certificate validation for the TLS interception feature.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-18227
|
2024-11-21 12:19 |
2018-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249654
|
5.5 |
MEDIUM
Local
|
jabberd2
|
jabberd2
|
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this ac…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-18226
|
2024-11-21 12:19 |
2018-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249655
|
7.8 |
HIGH
Local
|
jabberd2
|
jabberd2
|
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-18225
|
2024-11-21 12:19 |
2018-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249656
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel before 4.15, fs/ocfs2/aops.c omits use of a semaphore and consequently has a race condition for access to the extent tree during read operations in DIRECT mode, which allows local…
|
CWE-362
Race Condition
|
CVE-2017-18224
|
2024-11-21 12:19 |
2018-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249657
|
8.1 |
HIGH
Network
|
bmc
|
remedy_action_request_system
|
BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access.
|
CWE-287
Improper Authentication
|
CVE-2017-18223
|
2024-11-21 12:19 |
2018-03-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249658
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel before 4.12, Hisilicon Network Subsystem (HNS) does not consider the ETH_SS_PRIV_FLAGS case when retrieving sset_count data, which allows local users to cause a denial of service …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-18222
|
2024-11-21 12:19 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249659
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The __munlock_pagevec function in mm/mlock.c in the Linux kernel before 4.11.4 allows local users to cause a denial of service (NR_MLOCK accounting corruption) via crafted use of mlockall and munlock…
|
CWE-20
Improper Input Validation
|
CVE-2017-18221
|
2024-11-21 12:19 |
2018-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249660
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/blob.c CloseBlob use-after-free) or possibly have u…
|
CWE-416
Use After Free
|
CVE-2017-18220
|
2024-11-21 12:19 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|