|
251181
|
7.5 |
HIGH
Network
|
frrouting
|
frrouting
|
bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE…
|
CWE-200
Information Exposure
|
CVE-2017-15865
|
2024-11-21 12:15 |
2017-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251182
|
9.8 |
CRITICAL
Network
|
synology
|
carddav_server
|
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-f…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2017-15887
|
2024-11-21 12:15 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251183
|
7.8 |
HIGH
Local
|
hashicorp
|
vagrant
|
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
|
CWE-362
Race Condition
|
CVE-2017-16001
|
2024-11-21 12:15 |
2017-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251184
|
7.8 |
HIGH
Local
|
ignitum
|
sera
|
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user and system keychains to local attacks.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-15918
|
2024-11-21 12:15 |
2017-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251185
|
7.0 |
HIGH
Local
|
hashicorp
|
vagrant_vmware_fusion
|
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.
|
CWE-362
Race Condition
|
CVE-2017-15884
|
2024-11-21 12:15 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251186
|
7.8 |
HIGH
Local
|
flexense
|
syncbreeze
|
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long input into the "Destina…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15950
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251187
|
9.8 |
CRITICAL
Network
|
zomato_clone_script_project
|
zomato_clone_script
|
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-15993
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251188
|
9.8 |
CRITICAL
Network
|
website_broker_script_project
|
website_broker_script
|
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
|
CWE-89
SQL Injection
|
CVE-2017-15992
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251189
|
9.8 |
CRITICAL
Network
|
vastal
|
agent_zone
|
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type,…
|
CWE-89
SQL Injection
|
CVE-2017-15991
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251190
|
9.8 |
CRITICAL
Network
|
savsofteproducts
|
phpinventory
|
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15990
|
2024-11-21 12:15 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|