|
258351
|
8.8 |
HIGH
Network
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.
|
CWE-352
Origin Validation Error
|
CVE-2017-0362
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258352
|
7.8 |
HIGH
Local
|
mediawiki debian
|
mediawiki debian_linux
|
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.
|
CWE-200
Information Exposure
|
CVE-2017-0361
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258353
|
9.8 |
CRITICAL
Network
|
reproducible_builds debian
|
diffoscope debian_linux
|
diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive.
|
NVD-CWE-noinfo
|
CVE-2017-0359
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258354
|
7.8 |
HIGH
Local
|
tuxera debian
|
ntfs-3g debian_linux
|
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take a…
|
CWE-269
Improper Privilege Management
|
CVE-2017-0358
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258355
|
9.8 |
CRITICAL
Network
|
iucode-tool_project debian
|
iucode-tool debian_linux
|
A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-0357
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258356
|
9.8 |
CRITICAL
Network
|
ikiwiki debian
|
ikiwiki debian_linux
|
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.
|
CWE-287
Improper Authentication
|
CVE-2017-0356
|
2024-11-21 12:02 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258357
|
7.8 |
HIGH
Local
|
google
|
android
|
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-32573899.
|
NVD-CWE-noinfo
|
CVE-2017-0431
|
2024-11-21 12:02 |
2018-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258358
|
9.8 |
CRITICAL
Network
|
haxx
|
curl
|
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive informat…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-9953
|
2024-11-21 12:02 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258359
|
8.1 |
HIGH
Network
|
haxx
|
curl
|
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, makes it easier for remote attackers to conduct man-…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-9952
|
2024-11-21 12:02 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258360
|
5.4 |
MEDIUM
Network
|
f5
|
big-ip_advanced_firewall_manager
|
A SQL injection vulnerability exists in the BIG-IP AFM management UI on versions 12.0.0, 12.1.0, 12.1.1, 12.1.2 and 13.0.0 that may allow a copy of the firewall rules to be tampered with and impact t…
|
CWE-89
SQL Injection
|
CVE-2017-0304
|
2024-11-21 12:02 |
2017-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|