|
252151
|
5.5 |
MEDIUM
Local
|
freedesktop debian
|
poppler debian_linux
|
In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14928
|
2024-11-21 12:13 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252152
|
5.5 |
MEDIUM
Local
|
freedesktop
|
poppler
|
In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14927
|
2024-11-21 12:13 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252153
|
5.5 |
MEDIUM
Local
|
freedesktop debian
|
poppler debian_linux
|
In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14926
|
2024-11-21 12:13 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252154
|
8.0 |
HIGH
Network
|
tiki
|
tikiwiki_cms\/groupware
|
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global …
|
CWE-352
Origin Validation Error
|
CVE-2017-14925
|
2024-11-21 12:13 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252155
|
8.0 |
HIGH
Network
|
tiki
|
tikiwiki_cms\/groupware
|
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain adminis…
|
CWE-352
Origin Validation Error
|
CVE-2017-14924
|
2024-11-21 12:13 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252156
|
5.4 |
MEDIUM
Network
|
tine20
|
tine_2.0
|
Stored XSS vulnerability via IMG element at "Leadname" of CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14923
|
2024-11-21 12:13 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252157
|
5.4 |
MEDIUM
Network
|
tine20
|
tine_2.0
|
Stored XSS vulnerability via IMG element at "History" of Profile, Calendar, Tasks, and CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is m…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14922
|
2024-11-21 12:13 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252158
|
5.4 |
MEDIUM
Network
|
tine20
|
tine_2.0
|
Stored XSS vulnerability via IMG element at "Filename" of Filemanager in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rend…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14921
|
2024-11-21 12:13 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252159
|
6.1 |
MEDIUM
Network
|
egroupware
|
egroupware
|
Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14920
|
2024-11-21 12:13 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252160
|
9.8 |
CRITICAL
Network
|
filerun
|
filerun
|
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search f…
|
CWE-89
SQL Injection
|
CVE-2017-14738
|
2024-11-21 12:13 |
2017-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|