|
253241
|
7.8 |
HIGH
Local
|
artifex
|
mupdf
|
An integer overflow was discovered in pdf_read_new_xref_section in pdf/pdf-xref.c in Artifex MuPDF 1.11.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-15587
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253242
|
6.5 |
MEDIUM
Network
|
hitachienergy
|
fox515t_firmware
|
The embedded web server on ABB Fox515T 1.0 devices is vulnerable to Local File Inclusion. It accepts a parameter that specifies a file for display or for use as a template. The filename is not valida…
|
CWE-200
Information Exposure
|
CVE-2017-15583
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253243
|
9.8 |
CRITICAL
Network
|
phpsugar
|
php_melody
|
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.
|
CWE-89
SQL Injection
|
CVE-2017-15579
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253244
|
8.8 |
HIGH
Network
|
phpsugar
|
php_melody
|
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
|
CWE-89
SQL Injection
|
CVE-2017-15578
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253245
|
7.5 |
HIGH
Network
|
redmine debian
|
redmine debian_linux
|
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2017-15577
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253246
|
7.5 |
HIGH
Network
|
redmine debian
|
redmine debian_linux
|
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2017-15576
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253247
|
7.3 |
HIGH
Network
|
redmine debian
|
redmine debian_linux
|
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive d…
|
NVD-CWE-noinfo
|
CVE-2017-15575
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253248
|
6.1 |
MEDIUM
Network
|
redmine debian
|
redmine debian_linux
|
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15574
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253249
|
6.1 |
MEDIUM
Network
|
redmine debian
|
redmine debian_linux
|
In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15573
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253250
|
7.5 |
HIGH
Network
|
redmine debian
|
redmine debian_linux
|
In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, because account/lost_password does not use a redire…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-15572
|
2024-11-21 12:14 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|