|
250101
|
5.5 |
MEDIUM
Local
|
exiv2 canonical debian
|
exiv2 ubuntu_linux debian_linux
|
There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp in Exiv2 0.26. A crafted PNG file will lead to a remote denial of service attack.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17669
|
2024-11-21 12:18 |
2017-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250102
|
8.8 |
HIGH
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control bypass because the set of environments to which a …
|
CWE-862
Missing Authorization
|
CVE-2017-17665
|
2024-11-21 12:18 |
2017-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250103
|
5.9 |
MEDIUM
Network
|
digium
|
asterisk certified_asterisk
|
A Remote Crash issue was discovered in Asterisk Open Source 13.x before 13.18.4, 14.x before 14.7.4, and 15.x before 15.1.4 and Certified Asterisk before 13.13-cert9. Certain compound RTCP packets ca…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17664
|
2024-11-21 12:18 |
2017-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250104
|
9.8 |
CRITICAL
Network
|
entrepreneur_dating_script_project
|
entrepreneur_dating_script
|
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17648
|
2024-11-21 12:18 |
2017-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250105
|
5.9 |
MEDIUM
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware
|
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attack…
|
CWE-200
Information Exposure
|
CVE-2017-17549
|
2024-11-21 12:18 |
2017-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250106
|
7.5 |
HIGH
Network
|
mikrotik
|
routerboard
|
MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and sending data that begins with many '\0' characters, po…
|
CWE-20
Improper Input Validation
|
CVE-2017-17537
|
2024-11-21 12:18 |
2017-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250107
|
9.8 |
CRITICAL
Network
|
basic_job_site_script_project
|
basic_job_site_script
|
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
|
CWE-89
SQL Injection
|
CVE-2017-17642
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250108
|
9.8 |
CRITICAL
Network
|
resume_clone_script_project
|
resume_clone_script
|
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17641
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250109
|
9.8 |
CRITICAL
Network
|
advanced_world_database_project
|
advanced_world_database
|
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17640
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250110
|
9.8 |
CRITICAL
Network
|
muslim_matrimonial_script_project
|
muslim_matrimonial_script
|
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17639
|
2024-11-21 12:18 |
2017-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|