|
250991
|
9.8 |
CRITICAL
Network
|
pvpgn
|
stats
|
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter.
|
CWE-89
SQL Injection
|
CVE-2017-18291
|
2024-11-21 12:19 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250992
|
9.8 |
CRITICAL
Network
|
pvpgn
|
stats
|
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parameter.
|
CWE-89
SQL Injection
|
CVE-2017-18290
|
2024-11-21 12:19 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250993
|
9.8 |
CRITICAL
Network
|
pvpgn
|
stats
|
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter.
|
CWE-89
SQL Injection
|
CVE-2017-18289
|
2024-11-21 12:19 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250994
|
9.8 |
CRITICAL
Network
|
pvpgn
|
stats
|
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter.
|
CWE-89
SQL Injection
|
CVE-2017-18288
|
2024-11-21 12:19 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250995
|
9.8 |
CRITICAL
Network
|
pvpgn
|
stats
|
An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search parameter.
|
CWE-89
SQL Injection
|
CVE-2017-18287
|
2024-11-21 12:19 |
2018-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250996
|
7.8 |
HIGH
Local
|
google
|
android
|
A crafted binder request can cause an arbitrary unmap in MediaServer in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-18154
|
2024-11-21 12:19 |
2018-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250997
|
5.4 |
MEDIUM
Network
|
nzedb
|
nzedb
|
nZEDb v0.7.3.3 has XSS in the 404 error page.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18286
|
2024-11-21 12:19 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250998
|
7.1 |
HIGH
Local
|
burp_project
|
burp
|
The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveragi…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-18285
|
2024-11-21 12:19 |
2018-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250999
|
7.1 |
HIGH
Local
|
burp_project
|
burp
|
The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to th…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-18284
|
2024-11-21 12:19 |
2018-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251000
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhausti…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-18273
|
2024-11-21 12:19 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|