|
248411
|
6.1 |
MEDIUM
Network
|
qbittorrent
|
qbittorrent
|
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
|
CWE-20
Improper Input Validation
|
CVE-2017-6504
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248412
|
6.1 |
MEDIUM
Network
|
qbittorrent
|
qbittorrent
|
WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-6503
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248413
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
An issue was discovered in ImageMagick 6.9.7. A specially crafted webp file could lead to a file-descriptor leak in libmagickcore (thus, a DoS).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6502
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248414
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could lead to a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6501
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248415
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
An issue was discovered in ImageMagick 6.9.7. A specially crafted sun file triggers a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-6500
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248416
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
An issue was discovered in Magick++ in ImageMagick 6.9.7. A specially crafted file creating a nested exception could lead to a memory leak (thus, a DoS).
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-6499
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248417
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
An issue was discovered in ImageMagick 6.9.7. Incorrect TGA files could trigger assertion failures, thus leading to DoS.
|
CWE-20
Improper Input Validation
|
CVE-2017-6498
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248418
|
7.5 |
HIGH
Network
|
imagemagick
|
imagemagick
|
An issue was discovered in ImageMagick 6.9.7. A specially crafted psd file could lead to a NULL pointer dereference (thus, a DoS).
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6497
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248419
|
9.8 |
CRITICAL
Network
|
flexense
|
sysgauge
|
An issue was discovered in SysGauge 1.5.18. A buffer overflow vulnerability in SMTP connection verification leads to arbitrary code execution. The attack vector is a crafted SMTP daemon that sends a …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6416
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248420
|
8.1 |
HIGH
Network
|
wepresent
|
wipg-1500_firmware
|
The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DEBUG mode, an attacker can connect to the device u…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-6351
|
2024-11-21 12:29 |
2017-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|