|
252061
|
5.5 |
MEDIUM
Local
|
tcpdump
|
tcpdump
|
tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-16808
|
2024-11-21 12:17 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252062
|
5.4 |
MEDIUM
Network
|
getkirby
|
panel
|
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has been uploaded as a…
|
CWE-79
Cross-site Scripting
|
CVE-2017-16807
|
2024-11-21 12:17 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252063
|
7.5 |
HIGH
Network
|
ulterius
|
ulterius_server
|
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory traversal.
|
CWE-22
Path Traversal
|
CVE-2017-16806
|
2024-11-21 12:17 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252064
|
5.5 |
MEDIUM
Local
|
radare
|
radare2
|
In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, related to r_bin_dwarf_parse_comp_unit in dwarf.c …
|
CWE-125
Out-of-bounds Read
|
CVE-2017-16805
|
2024-11-21 12:17 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252065
|
4.3 |
MEDIUM
Network
|
redmine debian
|
redmine debian_linux
|
In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive …
|
CWE-200
Information Exposure
|
CVE-2017-16804
|
2024-11-21 12:17 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252066
|
7.5 |
HIGH
Network
|
libav
|
libav
|
In Libav through 11.11 and 12.x through 12.1, the smacker_decode_tree function in libavcodec/smacker.c does not properly restrict tree recursion, which allows remote attackers to cause a denial of se…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16803
|
2024-11-21 12:17 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252067
|
5.4 |
MEDIUM
Network
|
misp-project
|
misp
|
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16802
|
2024-11-21 12:17 |
2017-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252068
|
9.9 |
CRITICAL
Network
|
insteon
|
hub_firmware
|
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the…
|
-
|
CVE-2017-16323
|
2024-11-21 12:16 |
2023-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252069
|
9.9 |
CRITICAL
Network
|
insteon
|
hub_firmware
|
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the…
|
-
|
CVE-2017-16320
|
2024-11-21 12:16 |
2023-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252070
|
9.9 |
CRITICAL
Network
|
insteon
|
hub_firmware
|
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the…
|
-
|
CVE-2017-16312
|
2024-11-21 12:16 |
2023-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|