|
247481
|
8.8 |
HIGH
Network
|
netgear
|
dgn2200_firmware
|
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that pe…
|
CWE-352
Origin Validation Error
|
CVE-2017-6366
|
2024-11-21 12:29 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247482
|
6.5 |
MEDIUM
Local
|
virglrenderer_project
|
virglrenderer
|
Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via vectors involvi…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-6317
|
2024-11-21 12:29 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247483
|
6.5 |
MEDIUM
Local
|
virglrenderer_project
|
virglrenderer
|
The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process crash) by destroyin…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6210
|
2024-11-21 12:29 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247484
|
6.5 |
MEDIUM
Local
|
virglrenderer_project
|
virglrenderer
|
Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in virglrenderer before 0.6.0 allows local guest OS users to cause a den…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6209
|
2024-11-21 12:29 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247485
|
7.8 |
HIGH
Local
|
artifex debian
|
mupdf debian_linux
|
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-6060
|
2024-11-21 12:29 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247486
|
6.7 |
MEDIUM
Local
|
magnicomp
|
sysinfo
|
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-…
|
CWE-20
Improper Input Validation
|
CVE-2017-6516
|
2024-11-21 12:29 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247487
|
5.5 |
MEDIUM
Local
|
graphicsmagick
|
graphicsmagick
|
The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a small samp…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-6335
|
2024-11-21 12:29 |
2017-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247488
|
8.8 |
HIGH
Network
|
trendmicro
|
interscan_messaging_security_virtual_appliance
|
An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is …
|
CWE-78 NVD-CWE-noinfo
OS Command
|
CVE-2017-6398
|
2024-11-21 12:29 |
2017-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247489
|
7.5 |
HIGH
Network
|
cerberusftp
|
ftp_server
|
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an invalid Content-Length header.
|
CWE-20
Improper Input Validation
|
CVE-2017-6367
|
2024-11-21 12:29 |
2017-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247490
|
8.8 |
HIGH
Network
|
keekoonvision
|
kk002_ip_camera_firmware
|
Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entire set of other pages).
|
CWE-352
Origin Validation Error
|
CVE-2017-6180
|
2024-11-21 12:29 |
2017-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|