|
256161
|
5.4 |
MEDIUM
Network
|
cpanel
|
whm
|
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11441
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256162
|
4.9 |
MEDIUM
Network
|
sitecore
|
cms
|
In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScratchPad.aspx Reference parameter.
|
CWE-22
Path Traversal
|
CVE-2017-11440
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256163
|
5.4 |
MEDIUM
Network
|
sitecore
|
cms
|
In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11439
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256164
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-615
|
D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TELNET connection.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-11436
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256165
|
9.8 |
CRITICAL
Network
|
humaxdigital
|
hg100r_firmware
|
The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the route…
|
CWE-200
Information Exposure
|
CVE-2017-11435
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256166
|
7.5 |
HIGH
Network
|
wireshark
|
wireshark
|
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validati…
|
CWE-20
Improper Input Validation
|
CVE-2017-11411
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256167
|
7.5 |
HIGH
Network
|
wireshark
|
wireshark
|
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissecto…
|
CWE-20 CWE-835
Improper Input Validation Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-11410
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256168
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.
|
CWE-834
Excessive Iteration
|
CVE-2017-11409
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256169
|
7.5 |
HIGH
Network
|
wireshark
|
wireshark
|
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the AMQP dissector could crash. This was addressed in epan/dissectors/packet-amqp.c by checking for successful list dissection.
|
CWE-20
Improper Input Validation
|
CVE-2017-11408
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256170
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt.
|
CWE-20
Improper Input Validation
|
CVE-2017-11407
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|