|
251731
|
7.8 |
HIGH
Local
|
pnp4nagios
|
pnp4nagios
|
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging acc…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-16834
|
2024-11-21 12:17 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251732
|
6.1 |
MEDIUM
Network
|
gemirro_project
|
gemirro
|
Stored cross-site scripting (XSS) vulnerability in Gemirro before 0.16.0 allows attackers to inject arbitrary web script via a crafted javascript: URL in the "homepage" value of a ".gemspec" file.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16833
|
2024-11-21 12:17 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251733
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate size and offset values in the data dic…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-16832
|
2024-11-21 12:17 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251734
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which allows remote attackers to cause a denial of servi…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-16831
|
2024-11-21 12:17 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251735
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32-bit platforms, which allows remote attackers to cause a denial of service (seg…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-16830
|
2024-11-21 12:17 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251736
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The _bfd_elf_parse_gnu_properties function in elf-properties.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not prevent negative pointers, whi…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-16829
|
2024-11-21 12:17 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251737
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The display_debug_frames function in dwarf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (integer overflow and heap-based buffer over-read, and application crash) or p…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-16828
|
2024-11-21 12:17 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251738
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The aout_get_external_symbols function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16827
|
2024-11-21 12:17 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251739
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The coff_slurp_line_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16826
|
2024-11-21 12:17 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251740
|
5.4 |
MEDIUM
Network
|
b3log
|
symphony
|
b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client IP…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16821
|
2024-11-21 12:17 |
2017-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|