|
247441
|
7.0 |
HIGH
Local
|
ntp
|
ntp
|
NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable.
|
CWE-94
Code Injection
|
CVE-2017-6455
|
2024-11-21 12:29 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247442
|
7.8 |
HIGH
Local
|
ntp
|
ntp
|
Stack-based buffer overflow in the Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via an application path on the command line.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6452
|
2024-11-21 12:29 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247443
|
7.8 |
HIGH
Local
|
ntp
|
ntp
|
The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to e…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-6451
|
2024-11-21 12:29 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247444
|
8.8 |
HIGH
Network
|
intelliants
|
subrion_cms
|
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.
|
CWE-352
Origin Validation Error
|
CVE-2017-6069
|
2024-11-21 12:29 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247445
|
8.8 |
HIGH
Network
|
intelliants
|
subrion_cms
|
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.
|
CWE-352
Origin Validation Error
|
CVE-2017-6068
|
2024-11-21 12:29 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247446
|
6.1 |
MEDIUM
Network
|
getsymphony
|
symphony
|
Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6067
|
2024-11-21 12:29 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247447
|
8.8 |
HIGH
Network
|
intelliants
|
subrion_cms
|
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
|
CWE-352
Origin Validation Error
|
CVE-2017-6066
|
2024-11-21 12:29 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247448
|
8.8 |
HIGH
Network
|
eonweb_project
|
eonweb
|
EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3…
|
CWE-78
OS Command
|
CVE-2017-6087
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247449
|
8.8 |
HIGH
Network
|
firebirdsql
|
firebird
|
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
|
CWE-862
Missing Authorization
|
CVE-2017-6369
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247450
|
5.9 |
MEDIUM
Network
|
apparmor canonical
|
apparmor ubuntu_touch ubuntu_core
|
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have …
|
CWE-269
Improper Privilege Management
|
CVE-2017-6507
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|