|
253211
|
9.8 |
CRITICAL
Network
|
gnu
|
glibc
|
The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.c, related to the processing of home directories u…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15670
|
2024-11-21 12:14 |
2017-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253212
|
6.1 |
MEDIUM
Network
|
tp-link
|
tl-mr3220_firmware
|
Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description fi…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15291
|
2024-11-21 12:14 |
2017-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253213
|
6.7 |
MEDIUM
Local
|
paessler
|
prtg_network_monitor
|
PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of the error message.
|
CWE-20
Improper Input Validation
|
CVE-2017-15651
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253214
|
7.5 |
HIGH
Network
|
musl-libc
|
musl
|
musl libc before 1.1.17 has a buffer overflow via crafted DNS replies because dns_parse_callback in network/lookup_name.c does not restrict the number of addresses, and thus an attacker can provide a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15650
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253215
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race co…
|
CWE-362
Race Condition
|
CVE-2017-15649
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253216
|
6.1 |
MEDIUM
Network
|
phpsugar
|
php_melody
|
In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15648
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253217
|
7.5 |
HIGH
Network
|
fiberhome
|
routerfiberhome_firmware
|
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a crafted var:page value.
|
CWE-22
Path Traversal
|
CVE-2017-15647
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253218
|
6.1 |
MEDIUM
Network
|
webmin
|
webmin
|
Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Download from remote URL' option to download a file from a remote server. After set…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15646
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253219
|
8.8 |
HIGH
Network
|
webmin
|
webmin
|
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands.
|
CWE-352
Origin Validation Error
|
CVE-2017-15645
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253220
|
8.6 |
HIGH
Network
|
webmin
|
webmin
|
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-15644
|
2024-11-21 12:14 |
2017-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|