|
247311
|
5.5 |
MEDIUM
Local
|
libsamplerate_project debian
|
libsamplerate debian_linux
|
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-7697
|
2024-11-21 12:32 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247312
|
9.8 |
CRITICAL
Network
|
bigtreecms
|
bigtree_cms
|
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-7695
|
2024-11-21 12:32 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247313
|
8.8 |
HIGH
Network
|
getsymphony
|
symphony
|
Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. …
|
CWE-94
Code Injection
|
CVE-2017-7694
|
2024-11-21 12:32 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247314
|
9.8 |
CRITICAL
Network
|
sap
|
trex
|
A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592.
|
CWE-94
Code Injection
|
CVE-2017-7691
|
2024-11-21 12:32 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247315
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
homelynk_controller_lss100100_firmware
|
A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.
|
CWE-77
Command Injection
|
CVE-2017-7689
|
2024-11-21 12:32 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247316
|
6.1 |
MEDIUM
Network
|
auromeera
|
emli
|
Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code, generally in the form of a browser-side script, to a different…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7621
|
2024-11-21 12:32 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247317
|
8.1 |
HIGH
Network
|
foscam
|
fi9800xe r2 c1 fi9826p c1_lite fi9903p fi9928p fi9853ep fi9851p c2 fi9901ep fi9828p
|
Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging kn…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-7648
|
2024-11-21 12:32 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247318
|
8.8 |
HIGH
Network
|
solarwinds
|
log_\&_event_manager
|
SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.
|
NVD-CWE-noinfo
|
CVE-2017-7647
|
2024-11-21 12:32 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247319
|
6.5 |
MEDIUM
Network
|
solarwinds
|
log_\&_event_manager
|
SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.
|
CWE-200
Information Exposure
|
CVE-2017-7646
|
2024-11-21 12:32 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247320
|
9.8 |
CRITICAL
Network
|
fiyo
|
fiyo_cms
|
In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.
|
CWE-94
Code Injection
|
CVE-2017-7625
|
2024-11-21 12:32 |
2017-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|