|
252961
|
6.5 |
MEDIUM
Network
|
atlassian
|
fisheye
|
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are b…
|
CWE-200
Information Exposure
|
CVE-2017-18112
|
2024-11-21 12:19 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252962
|
5.9 |
MEDIUM
Network
|
bitcoin
|
bitcoin_core
|
bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server re…
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-18350
|
2024-11-21 12:19 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252963
|
6.5 |
MEDIUM
Network
|
atlassian
|
crowd
|
Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) …
|
CWE-352
Origin Validation Error
|
CVE-2017-18107
|
2024-11-21 12:19 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252964
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
|
CWE-20
Improper Input Validation
|
CVE-2017-18388
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252965
|
7.2 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
|
CWE-74
Injection
|
CVE-2017-18387
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252966
|
7.2 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
|
CWE-74
Injection
|
CVE-2017-18386
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252967
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
|
CWE-284
Improper Access Control
|
CVE-2017-18385
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252968
|
3.8 |
LOW
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
|
CWE-284
Improper Access Control
|
CVE-2017-18384
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252969
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18383
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252970
|
2.7 |
LOW
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
|
CWE-20
Improper Input Validation
|
CVE-2017-18382
|
2024-11-21 12:19 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|