|
255601
|
7.5 |
HIGH
Network
|
netapp
|
oncommand_unified_manager_for_clustered_data_ontap
|
NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, which makes it easier for remote attackers to captur…
|
CWE-200
Information Exposure
|
CVE-2017-14053
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255602
|
6.5 |
MEDIUM
Network
|
libzip debian
|
libzip debian_linux
|
The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-14107
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255603
|
7.8 |
HIGH
Local
|
aerohive
|
hivemanager_classic
|
HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive. An au…
|
CWE-20
Improper Input Validation
|
CVE-2017-14105
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255604
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering…
|
CWE-369
Divide By Zero
|
CVE-2017-14106
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255605
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote attackers to conduct …
|
CWE-416
Use After Free
|
CVE-2017-14103
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255606
|
7.8 |
HIGH
Local
|
mimedefang
|
mimedefang
|
MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account…
|
CWE-665
Improper Initialization
|
CVE-2017-14102
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255607
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.
|
CWE-89
SQL Injection
|
CVE-2017-14076
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255608
|
6.1 |
MEDIUM
Network
|
nexusphp
|
nexusphp
|
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14070
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255609
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.
|
CWE-89
SQL Injection
|
CVE-2017-14069
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255610
|
9.8 |
CRITICAL
Network
|
ruby-lang debian canonical redhat
|
ruby debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise…
|
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14064
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|