|
249561
|
5.5 |
MEDIUM
Local
|
freedesktop canonical redhat debian
|
poppler ubuntu_linux ansible_tower enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux
|
The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-18267
|
2024-11-21 12:19 |
2018-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249562
|
8.8 |
HIGH
Network
|
freedesktop debian canonical
|
xdg-utils debian_linux ubuntu_linux
|
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers…
|
CWE-74
Injection
|
CVE-2017-18266
|
2024-11-21 12:19 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249563
|
7.5 |
HIGH
Network
|
prosody debian
|
prosody debian_linux
|
Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket pa…
|
NVD-CWE-noinfo
|
CVE-2017-18265
|
2024-11-21 12:19 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249564
|
9.8 |
CRITICAL
Network
|
phpmyadmin debian
|
phpmyadmin debian_linux
|
An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false …
|
NVD-CWE-noinfo
|
CVE-2017-18264
|
2024-11-21 12:19 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249565
|
6.1 |
MEDIUM
Network
|
blackboard
|
blackboard_learn
|
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-au…
|
CWE-20 CWE-601
Improper Input Validation Open Redirect
|
CVE-2017-18262
|
2024-11-21 12:19 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249566
|
7.5 |
HIGH
Network
|
seagate
|
personal_cloud_firmware
|
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.
|
CWE-22
Path Traversal
|
CVE-2017-18263
|
2024-11-21 12:19 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249567
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The arch_timer_reg_read_stable macro in arch/arm64/include/asm/arch_timer.h in the Linux kernel before 4.13 allows local users to cause a denial of service (infinite recursion) by writing to a file u…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-18261
|
2024-11-21 12:19 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249568
|
5.4 |
MEDIUM
Network
|
atlassian
|
jira_server
|
The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability …
|
CWE-79
Cross-site Scripting
|
CVE-2017-18102
|
2024-11-21 12:19 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249569
|
7.5 |
HIGH
Network
|
qualcomm
|
sd_845_firmware sd_850_firmware
|
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile SD 845, SD 850, on a secure device, PD dumps are collected when debugging is not enabled.
|
NVD-CWE-noinfo
|
CVE-2017-18143
|
2024-11-21 12:19 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249570
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8909w_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_400_firmware sd_410_firmware sd_412_firmware sd_4…
|
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/1…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2017-18146
|
2024-11-21 12:19 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|