|
252341
|
6.1 |
MEDIUM
Network
|
nexusphp_project
|
nexusphp
|
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14534
|
2024-11-21 12:13 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252342
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.6-6 has a memory leak in ReadMATImage in coders/mat.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-14533
|
2024-11-21 12:13 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252343
|
9.8 |
CRITICAL
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.7-0 has a NULL Pointer Dereference in TIFFIgnoreTags in coders/tiff.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14532
|
2024-11-21 12:13 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252344
|
8.5 |
HIGH
Network
|
insteon
|
hub_firmware
|
Multiple exploitable buffer overflow vulnerabilities exists in the PubNub message handler for the "control" channel of Insteon Hub running firmware version 1012. Specially crafted replies received fr…
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-14454
|
2024-11-21 12:12 |
2023-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252345
|
10.0 |
CRITICAL
Network
|
ethereum
|
ethereum
|
An exploitable out-of-bounds read vulnerability exists in libevm (Ethereum Virtual Machine) of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read which can subseque…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-14451
|
2024-11-21 12:12 |
2020-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252346
|
7.8 |
HIGH
Local
|
zephyrproject
|
zephyr
|
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the shell component of Zephyr allows a serial or telnet connected user to cause a crash, possibly with arbitra…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14202
|
2024-11-21 12:12 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252347
|
7.8 |
HIGH
Local
|
zephyrproject
|
zephyr
|
Use After Free vulnerability in the Zephyr shell allows a serial or telnet connected user to cause denial of service, and possibly remote code execution. This issue affects: Zephyr shell versions pri…
|
CWE-416
Use After Free
|
CVE-2017-14201
|
2024-11-21 12:12 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252348
|
5.5 |
MEDIUM
Local
|
flif jasper_project
|
flif jasper
|
The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted flif fi…
|
CWE-399
Resource Management Errors
|
CVE-2017-14232
|
2024-11-21 12:12 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252349
|
6.1 |
MEDIUM
Network
|
forgerock
|
access_management openam
|
Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which al…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14395
|
2024-11-21 12:12 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252350
|
6.1 |
MEDIUM
Network
|
forgerock
|
access_management openam
|
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which a…
|
CWE-601
Open Redirect
|
CVE-2017-14394
|
2024-11-21 12:12 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|