|
249731
|
6.5 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version for 4.14.x), from version 5.0.0 before 5.0.9 (the fixed version for 5.0.x), fro…
|
CWE-22
Path Traversal
|
CVE-2017-18037
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249732
|
7.8 |
HIGH
Local
|
lcdf
|
gifsicle
|
A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-service attack or unspecified other impact via a maliciously crafted file, becau…
|
CWE-415
Double Free
|
CVE-2017-18120
|
2024-11-21 12:19 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249733
|
5.5 |
MEDIUM
Local
|
qemu debian canonical
|
qemu debian_linux ubuntu_linux
|
Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-18043
|
2024-11-21 12:19 |
2018-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249734
|
7.8 |
HIGH
Local
|
7-zip debian
|
7-zip p7zip debian_linux
|
Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potential…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-17969
|
2024-11-21 12:19 |
2018-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249735
|
7.8 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact becau…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-18079
|
2024-11-21 12:19 |
2018-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249736
|
7.8 |
HIGH
Local
|
systemd_project debian opensuse
|
systemd debian_linux leap
|
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass…
|
CWE-59
Link Following
|
CVE-2017-18078
|
2024-11-21 12:19 |
2018-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249737
|
7.5 |
HIGH
Network
|
brace_expansion_project
|
brace_expansion
|
index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.
|
CWE-20
Improper Input Validation
|
CVE-2017-18077
|
2024-11-21 12:19 |
2018-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249738
|
9.8 |
CRITICAL
Network
|
perfexcrm
|
perfex_crm
|
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-17976
|
2024-11-21 12:19 |
2018-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249739
|
7.5 |
HIGH
Network
|
omniauth debian
|
omniauth debian_linux
|
In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition to GET) parameters are stored in the session and become available in the enviro…
|
NVD-CWE-noinfo
|
CVE-2017-18076
|
2024-11-21 12:19 |
2018-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249740
|
7.8 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_…
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2017-18075
|
2024-11-21 12:19 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|