|
253191
|
5.4 |
MEDIUM
Network
|
mahara
|
mahara
|
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as ti…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15273
|
2024-11-21 12:14 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253192
|
9.1 |
CRITICAL
Network
|
xen
|
xen
|
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not mat…
|
CWE-119 CWE-200
Incorrect Access of Indexable Resource ('Range Error') Information Exposure
|
CVE-2017-15597
|
2024-11-21 12:14 |
2017-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253193
|
7.5 |
HIGH
Network
|
writediary
|
diary_with_lock
|
In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obta…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-15582
|
2024-11-21 12:14 |
2017-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253194
|
7.5 |
HIGH
Network
|
writediary
|
diary_with_lock
|
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-15581
|
2024-11-21 12:14 |
2017-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253195
|
9.8 |
CRITICAL
Network
|
ndocsoftware
|
ndoc
|
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-15366
|
2024-11-21 12:14 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253196
|
3.3 |
LOW
Local
|
gluster
|
glusterfs
|
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15096
|
2024-11-21 12:14 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253197
|
5.3 |
MEDIUM
Network
|
argosoft
|
mini_mail_server
|
Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an in…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-15223
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253198
|
9.8 |
CRITICAL
Network
|
nftp_project
|
nftp
|
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-15222
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253199
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
|
CWE-415
Double Free
|
CVE-2017-15186
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253200
|
9.8 |
CRITICAL
Network
|
phpsugar
|
php_melody
|
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
|
CWE-89
SQL Injection
|
CVE-2017-15081
|
2024-11-21 12:14 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|