|
250861
|
8.8 |
HIGH
Network
|
grandstream
|
ht802_firmware
|
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arb…
|
CWE-352
Origin Validation Error
|
CVE-2017-16565
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250862
|
5.4 |
MEDIUM
Network
|
grandstream
|
ht802_firmware
|
Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject arbitrary web script or HTML via the DHCP vendor …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16564
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250863
|
8.0 |
HIGH
Network
|
grandstream
|
ht802_firmware
|
Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update.
|
CWE-352
Origin Validation Error
|
CVE-2017-16563
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250864
|
8.8 |
HIGH
Network
|
hanwhasecurity
|
web_viewer
|
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrar…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-16524
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250865
|
9.8 |
CRITICAL
Network
|
samba debian canonical
|
rsync debian_linux ubuntu_linux
|
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-16548
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250866
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of s…
|
CWE-20
Improper Input Validation
|
CVE-2017-16547
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250867
|
8.8 |
HIGH
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uni…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16546
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250868
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType in…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-16545
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250869
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-16543
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250870
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
|
CWE-89
SQL Injection
|
CVE-2017-16542
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|