|
255661
|
7.8 |
HIGH
Local
|
pl32
|
photoline
|
A memory corruption vulnerability exists in the .TGA parsing functionality of Computerinsel Photoline 20.02. A specially crafted .TGA file can cause an out of bounds write resulting in potential code…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12106
|
2024-11-21 12:08 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255662
|
9.8 |
CRITICAL
Network
|
openvpn debian
|
openvpn debian_linux
|
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-12166
|
2024-11-21 12:08 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255663
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omi…
|
NVD-CWE-noinfo
|
CVE-2017-12154
|
2024-11-21 12:08 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255664
|
9.8 |
CRITICAL
Network
|
pureftpd fedoraproject
|
pure-ftpd fedora
|
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with defau…
|
NVD-CWE-noinfo
|
CVE-2017-12170
|
2024-11-21 12:08 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255665
|
4.4 |
MEDIUM
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-12153
|
2024-11-21 12:08 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255666
|
6.0 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) b…
|
-
|
CVE-2017-12168
|
2024-11-21 12:08 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255667
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
|
CWE-200
Information Exposure
|
CVE-2017-12157
|
2024-11-21 12:08 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255668
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12156
|
2024-11-21 12:08 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255669
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft E…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11766
|
2024-11-21 12:08 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255670
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scri…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11764
|
2024-11-21 12:08 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|