|
258341
|
7.5 |
HIGH
Network
|
webmproject
|
libwebp
|
In libwebp 0.5.1, there is a double free bug in libwebpmux.
|
CWE-415
Double Free
|
CVE-2016-9969
|
2024-11-21 12:02 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258342
|
9.8 |
CRITICAL
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.
|
CWE-74
Injection
|
CVE-2017-0372
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258343
|
5.3 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.
|
CWE-20
Improper Input Validation
|
CVE-2017-0370
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258344
|
6.5 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-0369
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258345
|
5.3 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.
|
CWE-20
Improper Input Validation
|
CVE-2017-0368
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258346
|
8.8 |
HIGH
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2017-0367
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258347
|
5.4 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.
|
CWE-20
Improper Input Validation
|
CVE-2017-0366
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258348
|
4.7 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.
|
CWE-79
Cross-site Scripting
|
CVE-2017-0365
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258349
|
6.1 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
|
CWE-601
Open Redirect
|
CVE-2017-0364
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258350
|
6.1 |
MEDIUM
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
|
CWE-601
Open Redirect
|
CVE-2017-0363
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|