|
249581
|
6.5 |
MEDIUM
Local
|
virglrenderer_project
|
virglrenderer
|
The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process crash) by destroyin…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6210
|
2024-11-21 12:29 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249582
|
6.5 |
MEDIUM
Local
|
virglrenderer_project
|
virglrenderer
|
Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in virglrenderer before 0.6.0 allows local guest OS users to cause a den…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6209
|
2024-11-21 12:29 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249583
|
7.8 |
HIGH
Local
|
artifex debian
|
mupdf debian_linux
|
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-6060
|
2024-11-21 12:29 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249584
|
6.7 |
MEDIUM
Local
|
magnicomp
|
sysinfo
|
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-…
|
CWE-20
Improper Input Validation
|
CVE-2017-6516
|
2024-11-21 12:29 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249585
|
5.5 |
MEDIUM
Local
|
graphicsmagick
|
graphicsmagick
|
The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a small samp…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-6335
|
2024-11-21 12:29 |
2017-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249586
|
8.8 |
HIGH
Network
|
trendmicro
|
interscan_messaging_security_virtual_appliance
|
An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is …
|
CWE-78 NVD-CWE-noinfo
OS Command
|
CVE-2017-6398
|
2024-11-21 12:29 |
2017-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249587
|
7.5 |
HIGH
Network
|
cerberusftp
|
ftp_server
|
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an invalid Content-Length header.
|
CWE-20
Improper Input Validation
|
CVE-2017-6367
|
2024-11-21 12:29 |
2017-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249588
|
8.8 |
HIGH
Network
|
keekoonvision
|
kk002_ip_camera_firmware
|
Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entire set of other pages).
|
CWE-352
Origin Validation Error
|
CVE-2017-6180
|
2024-11-21 12:29 |
2017-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249589
|
8.8 |
HIGH
Network
|
zammad
|
zammad
|
A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for u…
|
CWE-352
Origin Validation Error
|
CVE-2017-6081
|
2024-11-21 12:29 |
2017-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249590
|
9.8 |
CRITICAL
Network
|
zammad
|
zammad
|
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protection mechanism involving HTTP Access-Control headers. To exploit the vulnerabilit…
|
CWE-352
Origin Validation Error
|
CVE-2017-6080
|
2024-11-21 12:29 |
2017-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|