|
252871
|
4.8 |
MEDIUM
Network
|
igniterealtime
|
openfire
|
The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15911
|
2024-11-21 12:15 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252872
|
7.5 |
HIGH
Network
|
systemd_project canonical
|
systemd ubuntu_linux
|
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-re…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-15908
|
2024-11-21 12:15 |
2017-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252873
|
9.8 |
CRITICAL
Network
|
phpcollab
|
phpcollab
|
SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to newsdesk/newsdesk.php.
|
CWE-89
SQL Injection
|
CVE-2017-15907
|
2024-11-21 12:15 |
2017-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252874
|
7.5 |
HIGH
Network
|
londontrustmedia
|
private_internet_access
|
The London Trust Media Private Internet Access (PIA) application before 1.3.3.1 for Android allows remote attackers to cause a denial of service (application crash) via a large VPN server-list file.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-15882
|
2024-11-21 12:15 |
2017-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252875
|
9.8 |
CRITICAL
Network
|
dlink
|
dgs-1500_firmware
|
D-Link DGS-1500 Ax devices before 2.51B021 have a hardcoded password, which allows remote attackers to obtain shell access.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-15909
|
2024-11-21 12:15 |
2017-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252876
|
5.3 |
MEDIUM
Network
|
openbsd oracle debian netapp redhat
|
openssh sun_zfs_storage_appliance_kit debian_linux cloud_backup data_ontap_edge steelstore_cloud_integrated_storage clustered_data_ontap solidfire hci_management_node activ…
|
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-15906
|
2024-11-21 12:15 |
2017-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252877
|
6.1 |
MEDIUM
Network
|
axis
|
2100_network_camera_firmware
|
Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE:…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15885
|
2024-11-21 12:15 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252878
|
4.8 |
MEDIUM
Network
|
keystonejs
|
keystone
|
Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" fi…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15881
|
2024-11-21 12:15 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252879
|
7.2 |
HIGH
Network
|
eyesofnetwork
|
eyesofnetwork
|
SQL injection vulnerability vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the group_name paramet…
|
CWE-89
SQL Injection
|
CVE-2017-15880
|
2024-11-21 12:15 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252880
|
8.8 |
HIGH
Network
|
keystonejs
|
keystone
|
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a …
|
CWE-20
Improper Input Validation
|
CVE-2017-15879
|
2024-11-21 12:15 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|