|
251751
|
3.3 |
LOW
Local
|
gluster
|
glusterfs
|
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15096
|
2024-11-21 12:14 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251752
|
5.3 |
MEDIUM
Network
|
argosoft
|
mini_mail_server
|
Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an in…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-15223
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251753
|
9.8 |
CRITICAL
Network
|
nftp_project
|
nftp
|
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-15222
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251754
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
|
CWE-415
Double Free
|
CVE-2017-15186
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251755
|
9.8 |
CRITICAL
Network
|
phpsugar
|
php_melody
|
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
|
CWE-89
SQL Injection
|
CVE-2017-15081
|
2024-11-21 12:14 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251756
|
9.8 |
CRITICAL
Network
|
osticket
|
osticket
|
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15580
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251757
|
7.8 |
HIGH
Local
|
idemia
|
mso_1300_firmware
|
The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via …
|
NVD-CWE-noinfo
|
CVE-2017-15567
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251758
|
9.8 |
CRITICAL
Network
|
softwarepublico
|
e-sic
|
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
|
CWE-89
SQL Injection
|
CVE-2017-15381
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251759
|
6.1 |
MEDIUM
Network
|
softwarepublico
|
e-sic
|
XSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the requester's registration area) via the nome parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15380
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251760
|
9.8 |
CRITICAL
Network
|
softwarepublico
|
e-sic
|
An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
|
CWE-89
SQL Injection
|
CVE-2017-15379
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|