|
253201
|
9.8 |
CRITICAL
Network
|
osticket
|
osticket
|
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15580
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253202
|
7.8 |
HIGH
Local
|
idemia
|
mso_1300_firmware
|
The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via …
|
NVD-CWE-noinfo
|
CVE-2017-15567
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253203
|
9.8 |
CRITICAL
Network
|
softwarepublico
|
e-sic
|
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
|
CWE-89
SQL Injection
|
CVE-2017-15381
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253204
|
6.1 |
MEDIUM
Network
|
softwarepublico
|
e-sic
|
XSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the requester's registration area) via the nome parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15380
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253205
|
9.8 |
CRITICAL
Network
|
softwarepublico
|
e-sic
|
An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
|
CWE-89
SQL Injection
|
CVE-2017-15379
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253206
|
8.8 |
HIGH
Network
|
softwarepublico
|
e-sic
|
SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
|
CWE-89
SQL Injection
|
CVE-2017-15378
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253207
|
7.5 |
HIGH
Network
|
openinfosecfoundation
|
suricata
|
In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspection in detect-engi…
|
NVD-CWE-noinfo
|
CVE-2017-15377
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253208
|
7.5 |
HIGH
Network
|
irssi
|
irssi
|
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-15228
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253209
|
7.5 |
HIGH
Network
|
irssi
|
irssi
|
Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the stat…
|
CWE-416
Use After Free
|
CVE-2017-15227
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253210
|
5.9 |
MEDIUM
Network
|
gnu
|
glibc
|
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user na…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-15671
|
2024-11-21 12:14 |
2017-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|