|
251241
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
Use-after-free in the usbtv_probe function in drivers/media/usb/usbtv/usbtv-core.c in the Linux kernel through 4.14.10 allows attackers to cause a denial of service (system crash) or possibly have un…
|
CWE-416
Use After Free
|
CVE-2017-17975
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251242
|
9.8 |
CRITICAL
Network
|
basystems
|
bas920_firmware isc2000_firmware
|
BA SYSTEMS BAS Web on BAS920 devices (with Firmware 01.01.00*, HTTPserv 00002, and Script 02.*) and ISC2000 devices allows remote attackers to obtain sensitive information via a request for isc/get_s…
|
NVD-CWE-noinfo
|
CVE-2017-17974
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251243
|
8.8 |
HIGH
Network
|
libtiff
|
libtiff
|
In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue
|
CWE-416
Use After Free
|
CVE-2017-17973
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251244
|
6.1 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17971
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251245
|
6.1 |
MEDIUM
Network
|
netwin
|
surgeftp
|
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17933
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251246
|
9.8 |
CRITICAL
Network
|
xi-soft
|
nettransport_download_manager
|
A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP respons…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17968
|
2024-11-21 12:19 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251247
|
5.5 |
MEDIUM
Local
|
ksosoft
|
wps_office
|
pptreader.dll in Kingsoft WPS Office 10.1.0.6930 allows remote attackers to cause a denial of service via a crafted PPT file, aka CNVD-2017-35482.
|
CWE-20
Improper Input Validation
|
CVE-2017-17967
|
2024-11-21 12:19 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251248
|
8.8 |
HIGH
Network
|
php_multivendor_ecommerce_project
|
php_multivendor_ecommerce
|
PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.
|
CWE-352
Origin Validation Error
|
CVE-2017-17960
|
2024-11-21 12:19 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251249
|
9.8 |
CRITICAL
Network
|
php_multivendor_ecommerce_project
|
php_multivendor_ecommerce
|
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17959
|
2024-11-21 12:19 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251250
|
6.1 |
MEDIUM
Network
|
php_multivendor_ecommerce_project
|
php_multivendor_ecommerce
|
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17958
|
2024-11-21 12:19 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|