|
251201
|
9.8 |
CRITICAL
Network
|
muvikoscript
|
muviko
|
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php; the (2) season_id parameter to themes/flixer/aj…
|
CWE-89
SQL Injection
|
CVE-2017-17970
|
2024-11-21 12:19 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251202
|
5.3 |
MEDIUM
Network
|
parity
|
browser
|
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the c…
|
CWE-346
Origin Validation Error
|
CVE-2017-18016
|
2024-11-21 12:19 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251203
|
9.8 |
CRITICAL
Network
|
novosoft
|
handy_password
|
A buffer overflow in Handy Password 4.9.3 allows remote attackers to execute arbitrary code via a long "Title name" field in "mail box" data that is mishandled in an "Open from mail box" action.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17946
|
2024-11-21 12:19 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251204
|
6.1 |
MEDIUM
Network
|
avantfax
|
avantfax
|
AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18024
|
2024-11-21 12:19 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251205
|
6.1 |
MEDIUM
Network
|
officetracker
|
officetracker
|
Office Tracker 11.2.5 has XSS via the logincount parameter to the /otweb/OTPClientLogin URI.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18023
|
2024-11-21 12:19 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251206
|
8.8 |
HIGH
Network
|
redmine debian
|
redmine debian_linux
|
Redmine before 3.2.9, 3.3.x before 3.3.6, and 3.4.x before 3.4.4 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary comma…
|
NVD-CWE-noinfo
|
CVE-2017-18026
|
2024-11-21 12:19 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251207
|
9.8 |
CRITICAL
Network
|
innotube
|
itguard_manager
|
cgi-bin/drknow.cgi in Innotube ITGuard-Manager 0.0.0.1 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the username field, as demonstrated by a username beginning…
|
CWE-78
OS Command
|
CVE-2017-18025
|
2024-11-21 12:19 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251208
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
In ImageMagick 7.0.7-12 Q16, there are memory leaks in MontageImageCommand in MagickWand/montage.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-18022
|
2024-11-21 12:19 |
2018-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251209
|
9.8 |
CRITICAL
Network
|
qtpass
|
qtpass
|
It was discovered that QtPass before 1.2.1, when using the built-in password generator, generates possibly predictable and enumerable passwords. This only applies to the QtPass GUI.
|
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
|
CVE-2017-18021
|
2024-11-21 12:19 |
2018-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251210
|
8.4 |
HIGH
Local
|
samsung
|
samsung_mobile
|
On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs…
|
CWE-20
Improper Input Validation
|
CVE-2017-18020
|
2024-11-21 12:19 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|