|
256941
|
9.8 |
CRITICAL
Network
|
tcpdump
|
tcpdump
|
The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12895
|
2024-11-21 12:10 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256942
|
9.8 |
CRITICAL
Network
|
tcpdump
|
tcpdump
|
Several protocol parsers in tcpdump before 4.9.2 could cause a buffer over-read in addrtoname.c:lookup_bytestring().
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12894
|
2024-11-21 12:10 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256943
|
9.8 |
CRITICAL
Network
|
tcpdump
|
tcpdump
|
The SMB/CIFS parser in tcpdump before 4.9.2 has a buffer over-read in smbutil.c:name_len().
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12893
|
2024-11-21 12:10 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256944
|
9.8 |
CRITICAL
Network
|
opwglobal
|
sitesentinel_isite_atg_firmware sitesentinel_integra_500_firmware sitesentinel_integra_100_firmware
|
A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the fol…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-12733
|
2024-11-21 12:10 |
2017-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256945
|
9.8 |
CRITICAL
Network
|
opwglobal
|
sitesentinel_isite_atg_firmware sitesentinel_integra_500_firmware sitesentinel_integra_100_firmware
|
A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older…
|
CWE-89
SQL Injection
|
CVE-2017-12731
|
2024-11-21 12:10 |
2017-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256946
|
7.1 |
HIGH
Local
|
azeotech
|
daqfactory
|
An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with m…
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-12699
|
2024-11-21 12:10 |
2017-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256947
|
5.5 |
MEDIUM
Local
|
mp3gain
|
mp3gain
|
The "mpglibDBL/layer3.c" file in MP3Gain 1.5.2.r2 has a vulnerability which results in a read access violation when opening a crafted MP3 file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12912
|
2024-11-21 12:10 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256948
|
5.5 |
MEDIUM
Local
|
mp3gain
|
mp3gain
|
The "apetag.c" file in MP3Gain 1.5.2.r2 has a vulnerability which results in a stack memory corruption when opening a crafted MP3 file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12911
|
2024-11-21 12:10 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256949
|
6.1 |
MEDIUM
Network
|
nexusphp_project
|
nexusphp
|
Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) cheaters.php or (2) confirm_resend.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12906
|
2024-11-21 12:10 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256950
|
8.8 |
HIGH
Network
|
nexusphp_project
|
nexusphp
|
Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add …
|
CWE-352
Origin Validation Error
|
CVE-2017-12838
|
2024-11-21 12:10 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|