|
247141
|
7.8 |
HIGH
Local
|
linux debian
|
linux_kernel debian_linux
|
The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other …
|
CWE-415
Double Free
|
CVE-2017-8890
|
2024-11-21 12:34 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247142
|
6.8 |
MEDIUM
Physics
|
dolibarr
|
dolibarr_erp\/crm
|
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.
|
CWE-287
Improper Authentication
|
CVE-2017-8879
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247143
|
6.5 |
MEDIUM
Network
|
asus
|
rt-ac1750_firmware
|
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml.
|
CWE-200
Information Exposure
|
CVE-2017-8878
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247144
|
6.5 |
MEDIUM
Network
|
asus
|
rt-ac1750_firmware
|
ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.
|
CWE-200
Information Exposure
|
CVE-2017-8877
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247145
|
6.1 |
MEDIUM
Network
|
getsymphony
|
symphony
|
Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8876
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247146
|
6.5 |
MEDIUM
Network
|
codection
|
clean_login
|
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.
|
CWE-352
Origin Validation Error
|
CVE-2017-8875
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247147
|
8.8 |
HIGH
Network
|
acquia
|
mautic
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns or (2) delete cont…
|
CWE-352
Origin Validation Error
|
CVE-2017-8874
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247148
|
9.1 |
CRITICAL
Network
|
xmlsoft
|
libxml2
|
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-8872
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247149
|
7.5 |
HIGH
Network
|
flatcore
|
flatcore-cms
|
acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF.
|
CWE-22
Path Traversal
|
CVE-2017-8868
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247150
|
9.8 |
CRITICAL
Network
|
veritas
|
netbackup_appliance
|
In Veritas NetBackup Appliance 3.0 and earlier, unauthenticated users can execute arbitrary commands as root.
|
NVD-CWE-noinfo
|
CVE-2017-8859
|
2024-11-21 12:34 |
2017-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|