|
251031
|
8.0 |
HIGH
Network
|
grandstream
|
ht802_firmware
|
Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update.
|
CWE-352
Origin Validation Error
|
CVE-2017-16563
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251032
|
8.8 |
HIGH
Network
|
hanwhasecurity
|
web_viewer
|
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrar…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-16524
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251033
|
9.8 |
CRITICAL
Network
|
samba debian canonical
|
rsync debian_linux ubuntu_linux
|
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-16548
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251034
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of s…
|
CWE-20
Improper Input Validation
|
CVE-2017-16547
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251035
|
8.8 |
HIGH
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uni…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16546
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251036
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType in…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-16545
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251037
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-16543
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251038
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
|
CWE-89
SQL Injection
|
CVE-2017-16542
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251039
|
7.5 |
HIGH
Network
|
open-emr
|
openemr
|
OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR site to an arbitrary attacker-controlled MySQL serv…
|
CWE-200
Information Exposure
|
CVE-2017-16540
|
2024-11-21 12:16 |
2017-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251040
|
6.5 |
MEDIUM
Network
|
torproject redhat debian
|
tor enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus debian_linux
|
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages f…
|
CWE-200
Information Exposure
|
CVE-2017-16541
|
2024-11-21 12:16 |
2017-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|