|
252881
|
9.8 |
CRITICAL
Network
|
nftp_project
|
nftp
|
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-15222
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252882
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
|
CWE-415
Double Free
|
CVE-2017-15186
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252883
|
9.8 |
CRITICAL
Network
|
phpsugar
|
php_melody
|
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
|
CWE-89
SQL Injection
|
CVE-2017-15081
|
2024-11-21 12:14 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252884
|
9.8 |
CRITICAL
Network
|
osticket
|
osticket
|
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15580
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252885
|
7.8 |
HIGH
Local
|
idemia
|
mso_1300_firmware
|
The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via …
|
NVD-CWE-noinfo
|
CVE-2017-15567
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252886
|
9.8 |
CRITICAL
Network
|
softwarepublico
|
e-sic
|
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
|
CWE-89
SQL Injection
|
CVE-2017-15381
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252887
|
6.1 |
MEDIUM
Network
|
softwarepublico
|
e-sic
|
XSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the requester's registration area) via the nome parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15380
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252888
|
9.8 |
CRITICAL
Network
|
softwarepublico
|
e-sic
|
An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
|
CWE-89
SQL Injection
|
CVE-2017-15379
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252889
|
8.8 |
HIGH
Network
|
softwarepublico
|
e-sic
|
SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
|
CWE-89
SQL Injection
|
CVE-2017-15378
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252890
|
7.5 |
HIGH
Network
|
openinfosecfoundation
|
suricata
|
In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspection in detect-engi…
|
NVD-CWE-noinfo
|
CVE-2017-15377
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|