|
251631
|
8.8 |
HIGH
Network
|
fedoraproject mariadb percona
|
fedora mariadb xtradb_cluster
|
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with S…
|
NVD-CWE-noinfo
|
CVE-2017-15365
|
2024-11-21 12:14 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251632
|
4.3 |
MEDIUM
Network
|
emc
|
rsa_authentication_manager
|
The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerab…
|
CWE-89
SQL Injection
|
CVE-2017-15546
|
2024-11-21 12:14 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251633
|
8.1 |
HIGH
Network
|
fedoraproject
|
389_directory_server
|
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticate…
|
-
|
CVE-2017-15135
|
2024-11-21 12:14 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251634
|
9.8 |
CRITICAL
Network
|
symantec
|
reporter
|
Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to …
|
CWE-287
Improper Authentication
|
CVE-2017-15531
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251635
|
7.5 |
HIGH
Network
|
thekelleys
|
dnsmasq
|
A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostname…
|
NVD-CWE-noinfo
|
CVE-2017-15107
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251636
|
5.3 |
MEDIUM
Network
|
nlnetlabs debian canonical
|
unbound debian_linux ubuntu_linux
|
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) o…
|
CWE-20
Improper Input Validation
|
CVE-2017-15105
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251637
|
5.9 |
MEDIUM
Network
|
powerdns
|
recursor
|
An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-15094
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251638
|
6.1 |
MEDIUM
Network
|
powerdns
|
recursor
|
A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15092
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251639
|
5.3 |
MEDIUM
Network
|
powerdns
|
recursor
|
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized us…
|
CWE-20
Improper Input Validation
|
CVE-2017-15093
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251640
|
7.1 |
HIGH
Network
|
powerdns
|
authoritative
|
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the …
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2017-15091
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|