|
251211
|
7.1 |
HIGH
Local
|
k7computing
|
total_security
|
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a…
|
CWE-20
Improper Input Validation
|
CVE-2017-18019
|
2024-11-21 12:19 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251212
|
4.7 |
MEDIUM
Local
|
gnu
|
coreutils
|
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify …
|
CWE-362
Race Condition
|
CVE-2017-18018
|
2024-11-21 12:19 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251213
|
9.8 |
CRITICAL
Network
|
linux debian arista f5 suse opensuse openstack canonical redhat
|
linux_kernel debian_linux eos arx linux_enterprise_server linux_enterprise_software_development_kit linux_enterprise_debuginfo linux_enterprise_desktop linux_enterprise_real_t…
|
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memor…
|
CWE-416
Use After Free
|
CVE-2017-18017
|
2024-11-21 12:19 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251214
|
6.1 |
MEDIUM
Network
|
wp-unit
|
share_this_image
|
The ILLID Share This Image plugin before 1.04 for WordPress has XSS via the sharer.php url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18015
|
2024-11-21 12:19 |
2018-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251215
|
6.5 |
MEDIUM
Network
|
libtiff
|
libtiff
|
In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-18013
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251216
|
6.1 |
MEDIUM
Network
|
z-url_preview_project
|
z-url_preview
|
The Z-URL Preview plugin 1.6.1 for WordPress has XSS via the class.zlinkpreview.php url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18012
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251217
|
6.1 |
MEDIUM
Network
|
clickbank
|
affiliate_ads_for_clickbank_products
|
The MyCBGenie Affiliate Ads for Clickbank Products plugin through 1.6 for WordPress has XSS via the text_ads_ajax.php border_color parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18011
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251218
|
6.1 |
MEDIUM
Network
|
e-goi
|
smart_marketing_sms_and_newsletters_forms
|
The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18010
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251219
|
7.5 |
HIGH
Network
|
opencv
|
opencv
|
In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfmt_hdr.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-18009
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251220
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
In ImageMagick 7.0.7-17 Q16, there is a Memory Leak in ReadPWPImage in coders/pwp.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-18008
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|