|
256221
|
8.1 |
HIGH
Network
|
heimdal_project freebsd samba apple debian
|
heimdal freebsd samba mac_os_x iphone_os debian_linux
|
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2017-11103
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256222
|
9.8 |
CRITICAL
Network
|
xoops
|
xoops
|
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of …
|
CWE-89
SQL Injection
|
CVE-2017-11174
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256223
|
8.8 |
HIGH
Network
|
pulsesecure
|
pulse_connect_secure
|
Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malici…
|
CWE-352
Origin Validation Error
|
CVE-2017-11196
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256224
|
6.1 |
MEDIUM
Network
|
pulsesecure
|
pulse_connect_secure
|
Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11195
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256225
|
6.1 |
MEDIUM
Network
|
pulsesecure
|
pulse_connect_secure
|
Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter of adminservercacertdetails.cgi is reflected in the application's response and i…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11194
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256226
|
8.8 |
HIGH
Network
|
pulsesecure
|
pulse_connect_secure
|
Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These …
|
CWE-352
Origin Validation Error
|
CVE-2017-11193
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256227
|
7.8 |
HIGH
Local
|
rarzilla
|
unrar-free
|
unrarlib.c in unrar-free 0.0.1, when _DEBUG_LOG mode is enabled, might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspeci…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11190
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256228
|
6.5 |
MEDIUM
Network
|
rarzilla
|
unrar-free
|
unrarlib.c in unrar-free 0.0.1 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash), which could be relevant if unrarlib is used as library code …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-11189
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256229
|
7.5 |
HIGH
Network
|
imagemagick
|
imagemagick
|
The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted DPX file, related to lack of an EOF check.
|
CWE-834
Excessive Iteration
|
CVE-2017-11188
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256230
|
9.8 |
CRITICAL
Network
|
phpmyfaq
|
phpmyfaq
|
phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2017-11187
|
2024-11-21 12:07 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|