|
253171
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless …
|
CWE-200
Information Exposure
|
CVE-2017-15110
|
2024-11-21 12:14 |
2017-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253172
|
5.5 |
MEDIUM
Local
|
netapp
|
altavault_ost_plug-in
|
AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urged to move to a fixed version and change passwords used by …
|
CWE-200
Information Exposure
|
CVE-2017-15517
|
2024-11-21 12:14 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253173
|
8.8 |
HIGH
Network
|
netapp
|
snapcenter_server
|
NetApp SnapCenter Server versions 1.1 through 2.x are susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which could be used to cause an unintended authenticated action in the user inte…
|
CWE-352
Origin Validation Error
|
CVE-2017-15516
|
2024-11-21 12:14 |
2017-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253174
|
7.8 |
HIGH
Local
|
linux debian suse canonical
|
linux_kernel debian_linux linux_enterprise_server ubuntu_linux
|
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of…
|
CWE-416
Use After Free
|
CVE-2017-15115
|
2024-11-21 12:14 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253175
|
6.3 |
MEDIUM
Physics
|
linux redhat canonical
|
linux_kernel enterprise_linux ubuntu_linux
|
The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15102
|
2024-11-21 12:14 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253176
|
7.8 |
HIGH
Local
|
scala-lang
|
scala
|
The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, w…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-15288
|
2024-11-21 12:14 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253177
|
5.3 |
MEDIUM
Local
|
psftp
|
psftpd
|
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "…
|
CWE-287 CWE-522
Improper Authentication Insufficiently Protected Credentials
|
CVE-2017-15272
|
2024-11-21 12:14 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253178
|
5.9 |
MEDIUM
Network
|
psftp
|
psftpd
|
A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentication. The PSFTPd server did not automatically res…
|
CWE-416
Use After Free
|
CVE-2017-15271
|
2024-11-21 12:14 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253179
|
5.3 |
MEDIUM
Network
|
psftp
|
psftpd
|
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attackers to hide data in the Graphical User Interface…
|
CWE-20
Improper Input Validation
|
CVE-2017-15270
|
2024-11-21 12:14 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253180
|
4.3 |
MEDIUM
Network
|
psftp
|
psftpd
|
The PSFTPd 10.0.4 Build 729 server does not prevent FTP bounce scans by default. These can be performed using "nmap -b" and allow performing scans via the FTP server.
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2017-15269
|
2024-11-21 12:14 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|