|
257331
|
7.5 |
HIGH
Network
|
dtracker_project
|
dtracker
|
Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.
|
CWE-89
SQL Injection
|
CVE-2017-1002004
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257332
|
9.8 |
CRITICAL
Network
|
wp2android-turn-wp-site-into-android-app_project
|
wp2android-turn-wp-site-into-android-app
|
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002003
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257333
|
9.8 |
CRITICAL
Network
|
webapp-builder_project
|
webapp-builder
|
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002002
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257334
|
9.8 |
CRITICAL
Network
|
mobile-app-builder-by-wappress_project
|
mobile-app-builder-by-wappress
|
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002001
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257335
|
9.8 |
CRITICAL
Network
|
mobile-friendly-app-builder-by-easytouch_project
|
mobile-friendly-app-builder-by-easytouch
|
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1002000
|
2024-11-21 12:04 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257336
|
8.0 |
HIGH
Adjacent
|
linux debian nvidia redhat
|
linux_kernel debian_linux jetson_tk1 jetson_tx1 enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_…
|
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing …
|
CWE-787
Out-of-bounds Write
|
CVE-2017-1000251
|
2024-11-21 12:04 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257337
|
6.5 |
MEDIUM
Adjacent
|
bluez
|
bluez
|
All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd pr…
|
CWE-200
Information Exposure
|
CVE-2017-1000250
|
2024-11-21 12:04 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257338
|
5.5 |
MEDIUM
Local
|
file_project
|
file
|
An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000249
|
2024-11-21 12:04 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257339
|
7.8 |
HIGH
Local
|
gnome debian redhat
|
evince debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_server_…
|
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a fi…
|
NVD-CWE-noinfo
|
CVE-2017-1000083
|
2024-11-21 12:04 |
2017-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257340
|
5.4 |
MEDIUM
Network
|
oracle
|
hospitality_inventory_management
|
Vulnerability in the Oracle Hospitality Inventory Management component of Oracle Hospitality Applications (subcomponent: Settings and Config). Supported versions that are affected are 8.5.1 and 9.0.0…
|
NVD-CWE-noinfo
|
CVE-2017-10002
|
2024-11-21 12:04 |
2017-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|