|
247951
|
7.8 |
HIGH
Local
|
libxls_project debian
|
libxls debian_linux
|
An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execu…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-2919
|
2024-11-21 12:24 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247952
|
7.8 |
HIGH
Local
|
libxls_project
|
libxls
|
An exploitable out-of-bounds write vulnerability exists in the read_MSAT function of libxls 1.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An atta…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-2897
|
2024-11-21 12:24 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247953
|
7.8 |
HIGH
Local
|
libxls_project debian
|
libxls debian_linux
|
An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a memory corruption resulting in remote code execution.…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-2896
|
2024-11-21 12:24 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247954
|
5.5 |
MEDIUM
Local
|
apache debian redhat
|
openoffice debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_ser…
|
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrie…
|
CWE-200
Information Exposure
|
CVE-2017-3157
|
2024-11-21 12:24 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247955
|
7.8 |
HIGH
Local
|
apache
|
hadoop
|
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization me…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-3166
|
2024-11-21 12:24 |
2017-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247956
|
9.8 |
CRITICAL
Network
|
cesanta
|
mongoose
|
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while l…
|
CWE-416
Use After Free
|
CVE-2017-2922
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247957
|
9.8 |
CRITICAL
Network
|
cesanta
|
mongoose
|
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause an integer overflow, leading to …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-2921
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247958
|
8.8 |
HIGH
Network
|
meetcircle
|
circle_with_disney_firmware
|
An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker c…
|
CWE-78
OS Command
|
CVE-2017-2917
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247959
|
8.8 |
HIGH
Network
|
meetcircle
|
circle_with_disney_firmware
|
An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an arbitrary file to be overwrit…
|
CWE-59
Link Following
|
CVE-2017-2916
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247960
|
8.0 |
HIGH
Adjacent
|
meetcircle
|
circle_with_disney_firmware
|
An exploitable vulnerability exists in the WiFi configuration functionality of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary shell comm…
|
NVD-CWE-noinfo
|
CVE-2017-2915
|
2024-11-21 12:24 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|