|
247871
|
7.5 |
HIGH
Network
|
gstreamer_project
|
gstreamer
|
The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datet…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5838
|
2024-11-21 12:28 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247872
|
5.5 |
MEDIUM
Local
|
gstreamer_project
|
gstreamer
|
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception…
|
CWE-369
Divide By Zero
|
CVE-2017-5837
|
2024-11-21 12:28 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247873
|
5.9 |
MEDIUM
Network
|
citrix
|
netscaler_application_delivery_controller_firmware
|
Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GCM nonces, which makes it marginally easier for rem…
|
CWE-200
Information Exposure
|
CVE-2017-5933
|
2024-11-21 12:28 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247874
|
9.8 |
CRITICAL
Network
|
pear
|
html_ajax
|
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.
|
NVD-CWE-noinfo
|
CVE-2017-5677
|
2024-11-21 12:28 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247875
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to…
|
CWE-89
SQL Injection
|
CVE-2017-5879
|
2024-11-21 12:28 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247876
|
6.1 |
MEDIUM
Network
|
dotcms
|
dotcms
|
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5877
|
2024-11-21 12:28 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247877
|
6.1 |
MEDIUM
Network
|
dotcms
|
dotcms
|
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5876
|
2024-11-21 12:28 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247878
|
5.4 |
MEDIUM
Network
|
dotcms
|
dotcms
|
XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5875
|
2024-11-21 12:28 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247879
|
6.1 |
MEDIUM
Network
|
sanadata
|
sanacms
|
Cross-site scripting (XSS) vulnerability in index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-5882
|
2024-11-21 12:28 |
2017-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247880
|
6.5 |
MEDIUM
Network
|
splunk
|
splunk
|
Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x before 6.0.13, 5.0.x before 5.0.17 and Splunk Ligh…
|
CWE-20
Improper Input Validation
|
CVE-2017-5880
|
2024-11-21 12:28 |
2017-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|