|
252161
|
9.8 |
CRITICAL
Network
|
samba debian canonical
|
rsync debian_linux ubuntu_linux
|
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-16548
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252162
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of s…
|
CWE-20
Improper Input Validation
|
CVE-2017-16547
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252163
|
8.8 |
HIGH
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uni…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16546
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252164
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType in…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-16545
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252165
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-16543
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252166
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
|
CWE-89
SQL Injection
|
CVE-2017-16542
|
2024-11-21 12:16 |
2017-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252167
|
7.5 |
HIGH
Network
|
open-emr
|
openemr
|
OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR site to an arbitrary attacker-controlled MySQL serv…
|
CWE-200
Information Exposure
|
CVE-2017-16540
|
2024-11-21 12:16 |
2017-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252168
|
6.5 |
MEDIUM
Network
|
torproject redhat debian
|
tor enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus debian_linux
|
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages f…
|
CWE-200
Information Exposure
|
CVE-2017-16541
|
2024-11-21 12:16 |
2017-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252169
|
5.9 |
MEDIUM
Network
|
mobyproject
|
moby
|
The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels a…
|
CWE-200
Information Exposure
|
CVE-2017-16539
|
2024-11-21 12:16 |
2017-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252170
|
6.6 |
MEDIUM
Physics
|
linux
|
linux_kernel
|
drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified oth…
|
CWE-20
Improper Input Validation
|
CVE-2017-16538
|
2024-11-21 12:16 |
2017-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|