|
250481
|
5.3 |
MEDIUM
Network
|
wordpress
|
wordpress
|
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote…
|
CWE-200
Information Exposure
|
CVE-2017-5487
|
2024-11-21 12:27 |
2017-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250482
|
8.8 |
HIGH
Network
|
s9y
|
serendipity
|
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
|
CWE-352
Origin Validation Error
|
CVE-2017-5476
|
2024-11-21 12:27 |
2017-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250483
|
8.8 |
HIGH
Network
|
s9y
|
serendipity
|
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
|
CWE-352
Origin Validation Error
|
CVE-2017-5475
|
2024-11-21 12:27 |
2017-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250484
|
6.1 |
MEDIUM
Network
|
s9y
|
serendipity
|
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer hea…
|
CWE-601
Open Redirect
|
CVE-2017-5474
|
2024-11-21 12:27 |
2017-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250485
|
8.8 |
HIGH
Network
|
ntop
|
ntopng
|
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user…
|
CWE-352
Origin Validation Error
|
CVE-2017-5473
|
2024-11-21 12:27 |
2017-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250486
|
7.8 |
HIGH
Local
|
foxitsoftware
|
foxit_pdf_toolkit
|
Memory Corruption Vulnerability in Foxit PDF Toolkit v1.3 allows an attacker to cause Denial of Service and Remote Code Execution when the victim opens the specially crafted PDF file. The Vulnerabili…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5364
|
2024-11-21 12:27 |
2017-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250487
|
9.8 |
CRITICAL
Network
|
libtiff
|
libtiff
|
LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5225
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250488
|
7.5 |
HIGH
Network
|
samsung
|
samsung_mobile
|
Samsung Note devices with KK(4.4), L(5.0/5.1), and M(6.0) software allow attackers to crash the system by creating an arbitrarily large number of active VR service threads. The Samsung ID is SVE-2016…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-5351
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250489
|
7.5 |
HIGH
Network
|
samsung
|
samsung_mobile
|
Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allow attackers to crash systemUI by leveraging incomplete exception handling. The Samsung ID is SVE-2016-7122.
|
NVD-CWE-noinfo
|
CVE-2017-5350
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250490
|
7.2 |
HIGH
Network
|
metalgenix
|
genixcms
|
SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/ind…
|
CWE-89
SQL Injection
|
CVE-2017-5347
|
2024-11-21 12:27 |
2017-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|