|
251951
|
7.5 |
HIGH
Network
|
digium
|
certified_asterisk asterisk
|
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP …
|
CWE-459
Incomplete Cleanup
|
CVE-2017-17090
|
2024-11-21 12:17 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251952
|
7.5 |
HIGH
Network
|
zte
|
zxdsl_831cii_firmware
|
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET requ…
|
CWE-287
Improper Authentication
|
CVE-2017-16953
|
2024-11-21 12:17 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251953
|
7.8 |
HIGH
Local
|
arqbackup
|
arq
|
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-16895
|
2024-11-21 12:17 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251954
|
6.5 |
MEDIUM
Network
|
piwigo
|
piwigo
|
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context…
|
CWE-89
SQL Injection
|
CVE-2017-16893
|
2024-11-21 12:17 |
2017-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251955
|
5.5 |
MEDIUM
Local
|
vim debian canonical
|
vim debian_linux ubuntu_linux
|
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local user…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2017-17087
|
2024-11-21 12:17 |
2017-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251956
|
9.8 |
CRITICAL
Network
|
inedo
|
otter
|
Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact, as…
|
CWE-20
Improper Input Validation
|
CVE-2017-17086
|
2024-11-21 12:17 |
2017-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251957
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2017-17085
|
2024-11-21 12:17 |
2017-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251958
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was addressed in epan/dissectors/packet-iwarp-mpa.c by validating a ULPDU length.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2017-17084
|
2024-11-21 12:17 |
2017-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251959
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was addressed in epan/dissectors/packet-netbios.c by ensuring that write operations are bounded by the beginni…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2017-17083
|
2024-11-21 12:17 |
2017-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251960
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does not properly validate widths and heights, which allows remote attackers to cause a denial of service (integer signedne…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17081
|
2024-11-21 12:17 |
2017-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|