|
251811
|
9.8 |
CRITICAL
Network
|
zorovavi\/blog_project
|
zorovavi\/blog
|
SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.
|
CWE-89
SQL Injection
|
CVE-2017-15539
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251812
|
5.4 |
MEDIUM
Network
|
ilias
|
ilias
|
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to th…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15538
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251813
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feature but not the xsaves feature, does not correctly handle attempts to set reserv…
|
CWE-200
Information Exposure
|
CVE-2017-15537
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251814
|
7.8 |
HIGH
Local
|
radare
|
radare2
|
The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15385
|
2024-11-21 12:14 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251815
|
6.0 |
MEDIUM
Local
|
qemu
|
qemu
|
The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors rel…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-15289
|
2024-11-21 12:14 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251816
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2017-15265
|
2024-11-21 12:14 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251817
|
7.8 |
HIGH
Local
|
asx_to_mp3_converter_project
|
asx_to_mp3_converter
|
ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15221
|
2024-11-21 12:14 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251818
|
6.1 |
MEDIUM
Network
|
phpjabbers
|
rate_me
|
rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15384
|
2024-11-21 12:14 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251819
|
7.8 |
HIGH
Local
|
nero
|
nero
|
Nero 7.10.1.0 has an unquoted BINARY_PATH_NAME for NBService, exploitable via a Trojan horse Nero.exe file in the %PROGRAMFILES(x86)%\Nero directory.
|
CWE-428
Unquoted Search Path or Element
|
CVE-2017-15383
|
2024-11-21 12:14 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251820
|
7.5 |
HIGH
Network
|
sap
|
host_agent
|
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.
|
CWE-287
Improper Authentication
|
CVE-2017-15297
|
2024-11-21 12:14 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|