|
256261
|
6.1 |
MEDIUM
Network
|
phpldapadmin_project debian
|
phpldapadmin debian_linux
|
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11107
|
2024-11-21 12:07 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256262
|
5.9 |
MEDIUM
Network
|
knot-dns debian
|
knot_dns debian_linux
|
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if …
|
CWE-20
Improper Input Validation
|
CVE-2017-11104
|
2024-11-21 12:07 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256263
|
7.5 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The ReadOneJNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (application crash) during JNG reading via a zero-length color_image data st…
|
CWE-20
Improper Input Validation
|
CVE-2017-11102
|
2024-11-21 12:07 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256264
|
8.8 |
HIGH
Network
|
swftools
|
swftools
|
When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_Relocate() function in lib/modules/swftools.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-11101
|
2024-11-21 12:07 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256265
|
8.8 |
HIGH
Network
|
swftools
|
swftools
|
When SWFTools 0.9.2 processes a crafted file in swfextract, it can lead to a NULL Pointer Dereference in the swf_FoldSprite() function in lib/rxfswf.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-11100
|
2024-11-21 12:07 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256266
|
8.8 |
HIGH
Network
|
swftools
|
swftools
|
When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Violation in the wav_convert2mono() function in lib/wav.c.
|
CWE-20
Improper Input Validation
|
CVE-2017-11099
|
2024-11-21 12:07 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256267
|
8.8 |
HIGH
Network
|
swftools
|
swftools
|
When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.
|
CWE-20
Improper Input Validation
|
CVE-2017-11098
|
2024-11-21 12:07 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256268
|
8.8 |
HIGH
Network
|
swftools
|
swftools
|
When SWFTools 0.9.2 processes a crafted file in swfc, it can lead to a NULL Pointer Dereference in the dict_lookup() function in lib/q.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-11097
|
2024-11-21 12:07 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256269
|
8.8 |
HIGH
Network
|
swftools
|
swftools
|
When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_DeleteFilter() function in lib/modules/swffilter.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-11096
|
2024-11-21 12:07 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256270
|
9.8 |
CRITICAL
Network
|
hp
|
storage_essentials
|
In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-10992
|
2024-11-21 12:06 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|