|
253301
|
5.5 |
MEDIUM
Local
|
exiv2
|
exiv2
|
There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14858
|
2024-11-21 12:13 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253302
|
5.5 |
MEDIUM
Local
|
exiv2
|
exiv2
|
In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a denial of service attack.
|
CWE-416
Use After Free
|
CVE-2017-14857
|
2024-11-21 12:13 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253303
|
7.5 |
HIGH
Network
|
nodejs
|
node.js
|
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
|
CWE-22
Path Traversal
|
CVE-2017-14849
|
2024-11-21 12:13 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253304
|
8.8 |
HIGH
Network
|
dasinfomedia
|
wpams_apartment_management_system
|
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-14847
|
2024-11-21 12:13 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253305
|
8.8 |
HIGH
Network
|
dasinfomedia
|
hospital_management_system
|
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-14846
|
2024-11-21 12:13 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253306
|
8.8 |
HIGH
Network
|
dasinfomedia
|
wpchurch_church_management_system
|
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-14845
|
2024-11-21 12:13 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253307
|
8.8 |
HIGH
Network
|
dasinfomedia
|
wpgym_gym_management_system
|
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-14844
|
2024-11-21 12:13 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253308
|
8.8 |
HIGH
Network
|
dasinfomedia
|
school_management_system
|
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-14843
|
2024-11-21 12:13 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253309
|
8.8 |
HIGH
Network
|
dasinfomedia
|
smsmaster_multipurpose_sms_gateway
|
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-14842
|
2024-11-21 12:13 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253310
|
6.5 |
MEDIUM
Network
|
dasinfomedia
|
annual_maintenance_contract_management_system
|
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-14841
|
2024-11-21 12:13 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|