|
248381
|
9.8 |
CRITICAL
Network
|
tibco
|
spotfire_client spotfire_web_player_client spotfire_analyst spotfire_connectors spotfire_deployment_kit spotfire_desktop spotfire_desktop_language_packs
|
Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these iss…
|
CWE-89
SQL Injection
|
CVE-2017-3181
|
2024-11-21 12:24 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248382
|
5.4 |
MEDIUM
Network
|
tibco
|
spotfire_automation_services spotfire_desktop spotfire_professional spotfire_web_player spotfire_deployment_kit silver_fabric_enabler_for_spotfire_web_player spotfire_analyst spo…
|
Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to exec…
|
CWE-79
Cross-site Scripting
|
CVE-2017-3180
|
2024-11-21 12:24 |
2018-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248383
|
7.5 |
HIGH
Network
|
natus
|
xltek_neuroworks
|
An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, re…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-2860
|
2024-11-21 12:24 |
2018-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248384
|
7.5 |
HIGH
Network
|
natus
|
xltek_neuroworks
|
An exploitable denial-of-service vulnerability exists in the traversal of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, resultin…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-2858
|
2024-11-21 12:24 |
2018-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248385
|
7.5 |
HIGH
Network
|
natus
|
xltek_neuroworks
|
An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, re…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-2852
|
2024-11-21 12:24 |
2018-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248386
|
8.1 |
HIGH
Network
|
igniterealtime
|
user_import_export
|
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. …
|
CWE-611
XXE
|
CVE-2017-2815
|
2024-11-21 12:24 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248387
|
8.8 |
HIGH
Network
|
freexl_project debian
|
freexl debian_linux
|
An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote code ex…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-2924
|
2024-11-21 12:24 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248388
|
8.8 |
HIGH
Network
|
freexl_project debian
|
freexl debian_linux
|
An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file can cause a memory corruption resulting in remote …
|
CWE-787
Out-of-bounds Write
|
CVE-2017-2923
|
2024-11-21 12:24 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248389
|
7.8 |
HIGH
Local
|
blender debian
|
blender debian_linux
|
An exploitable integer overflow exists in the Image loading functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-2918
|
2024-11-21 12:24 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248390
|
7.8 |
HIGH
Local
|
blender debian
|
blender debian_linux
|
An exploitable integer overflow exists in the thumbnail functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted .blend file can cause an integer overflow resulti…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-2908
|
2024-11-21 12:24 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|