|
253251
|
6.1 |
MEDIUM
Network
|
redmine debian
|
redmine debian_linux
|
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15571
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253252
|
6.1 |
MEDIUM
Network
|
redmine debian
|
redmine debian_linux
|
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/timelog/_list.html.erb via crafted column data.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15570
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253253
|
6.1 |
MEDIUM
Network
|
redmine debian
|
redmine debian_linux
|
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/queries_helper.rb via a multi-value field with a crafted value that is mishandled during rendering of an…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15569
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253254
|
6.1 |
MEDIUM
Network
|
redmine debian
|
redmine debian_linux
|
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/helpers/application_helper.rb via a multi-value field with a crafted value that is mishandled during rendering o…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15568
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253255
|
8.8 |
HIGH
Network
|
freedesktop debian
|
poppler debian_linux
|
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15565
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253256
|
9.8 |
CRITICAL
Network
|
zorovavi\/blog_project
|
zorovavi\/blog
|
SQL Injection exists in zorovavi/blog through 2017-10-17 via the id parameter to recept.php.
|
CWE-89
SQL Injection
|
CVE-2017-15539
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253257
|
5.4 |
MEDIUM
Network
|
ilias
|
ilias
|
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to th…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15538
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253258
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feature but not the xsaves feature, does not correctly handle attempts to set reserv…
|
CWE-200
Information Exposure
|
CVE-2017-15537
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253259
|
7.8 |
HIGH
Local
|
radare
|
radare2
|
The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15385
|
2024-11-21 12:14 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253260
|
6.0 |
MEDIUM
Local
|
qemu
|
qemu
|
The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial of service (out-of-bounds write access and Qemu process crash) via vectors rel…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-15289
|
2024-11-21 12:14 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|