|
248141
|
7.8 |
HIGH
Local
|
trendmicro
|
endpoint_sensor
|
Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code, aka Trend Micro Vulnerability Identifier 2015-0208.
|
CWE-426
Untrusted Search Path
|
CVE-2017-6798
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248142
|
5.5 |
MEDIUM
Local
|
partclone_project
|
partclone
|
partclone.chkimg in partclone 0.2.89 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to launch a 'Denial o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6596
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248143
|
6.1 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'action_type' par…
|
CWE-79
Cross-site Scripting
|
CVE-2017-6797
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248144
|
6.1 |
MEDIUM
Network
|
django-epiceditor_project
|
django-epiceditor
|
There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6591
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248145
|
6.3 |
MEDIUM
Physics
|
canonical
|
ubuntu_linux
|
An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login s…
|
CWE-863
Incorrect Authorization
|
CVE-2017-6590
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248146
|
6.1 |
MEDIUM
Network
|
epiceditor_project
|
epiceditor
|
EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6589
|
2024-11-21 12:30 |
2017-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248147
|
7.2 |
HIGH
Network
|
mail-masta_project
|
mail-masta
|
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: subscri…
|
CWE-89
SQL Injection
|
CVE-2017-6578
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248148
|
7.2 |
HIGH
Network
|
mail-masta_project
|
mail-masta
|
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: list_id.
|
CWE-89
SQL Injection
|
CVE-2017-6577
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248149
|
7.2 |
HIGH
Network
|
mail-masta_project
|
mail-masta
|
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/campaign-delete.php with the GET Parameter:…
|
CWE-89
SQL Injection
|
CVE-2017-6576
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248150
|
7.2 |
HIGH
Network
|
mail-masta_project
|
mail-masta
|
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: member…
|
CWE-89
SQL Injection
|
CVE-2017-6575
|
2024-11-21 12:30 |
2017-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|