|
251171
|
6.5 |
MEDIUM
Network
|
synology
|
calendar
|
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2017-15891
|
2024-11-21 12:15 |
2017-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251172
|
7.8 |
HIGH
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a craf…
|
CWE-20
Improper Input Validation
|
CVE-2017-15868
|
2024-11-21 12:15 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251173
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overflow can occur while reading firmware logs.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15813
|
2024-11-21 12:15 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251174
|
8.8 |
HIGH
Network
|
synology
|
diskstation_manager
|
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.
|
CWE-77
Command Injection
|
CVE-2017-15889
|
2024-11-21 12:15 |
2017-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251175
|
6.2 |
MEDIUM
Local
|
apache netapp oracle
|
struts oncommand_balance weblogic_server jd_edwards_enterpriseone_tools retail_xstore_point_of_service financial_services_market_risk_measurement_and_management webcenter_portal …
|
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
|
CWE-20
Improper Input Validation
|
CVE-2017-15707
|
2024-11-21 12:15 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251176
|
9.8 |
CRITICAL
Network
|
apache
|
qpid_broker-j
|
In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a rem…
|
NVD-CWE-noinfo
|
CVE-2017-15702
|
2024-11-21 12:15 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251177
|
7.5 |
HIGH
Network
|
apache
|
qpid_broker-j
|
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-15701
|
2024-11-21 12:15 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251178
|
8.8 |
HIGH
Network
|
otrs debian
|
otrs debian_linux
|
In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password.
|
NVD-CWE-noinfo
|
CVE-2017-15864
|
2024-11-21 12:15 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251179
|
7.5 |
HIGH
Network
|
konversation debian
|
konversation debian_linux
|
Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing of IRC color formatting codes.
|
NVD-CWE-noinfo
|
CVE-2017-15923
|
2024-11-21 12:15 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251180
|
8.1 |
HIGH
Network
|
zetacomponents
|
mail
|
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow rem…
|
CWE-94
Code Injection
|
CVE-2017-15806
|
2024-11-21 12:15 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|