|
252151
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
An issue was discovered in net/rds/af_rds.c in the Linux kernel before 4.11. There is an out of bounds write and read in the function rds_recv_track_latency.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-18552
|
2024-11-21 12:20 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252152
|
6.7 |
MEDIUM
Local
|
linux opensuse
|
linux_kernel leap
|
An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux kernel before 4.14.15. There is an out of bounds write in the function i2c_smbus_xfer_emulated.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-18551
|
2024-11-21 12:20 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252153
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_get_hba_info does not initialize the hbainfo…
|
CWE-200
Information Exposure
|
CVE-2017-18550
|
2024-11-21 12:20 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252154
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_send_raw_srb does not initialize the reply s…
|
CWE-200
Information Exposure
|
CVE-2017-18549
|
2024-11-21 12:20 |
2019-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252155
|
8.8 |
HIGH
Network
|
neliosoftware
|
nelio_ab_testing
|
The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
|
CWE-352
Origin Validation Error
|
CVE-2017-18547
|
2024-11-21 12:20 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252156
|
8.8 |
HIGH
Network
|
jayj_quicktag_project
|
jayj_quicktag
|
The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2017-18546
|
2024-11-21 12:20 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252157
|
7.5 |
HIGH
Network
|
invite_anyone_project
|
invite_anyone
|
The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.
|
CWE-20
Improper Input Validation
|
CVE-2017-18545
|
2024-11-21 12:20 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252158
|
8.8 |
HIGH
Network
|
invite_anyone_project
|
invite_anyone
|
The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2017-18544
|
2024-11-21 12:20 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252159
|
9.8 |
CRITICAL
Network
|
invite_anyone_project
|
invite_anyone
|
The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
|
CWE-284
Improper Access Control
|
CVE-2017-18543
|
2024-11-21 12:20 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252160
|
6.1 |
MEDIUM
Network
|
bestwebsoft
|
zendesk_help_center
|
The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18542
|
2024-11-21 12:20 |
2019-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|