|
246891
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandled in the _yr_re_em…
|
CWE-674
Uncontrolled Recursion
|
CVE-2017-9438
|
2024-11-21 12:36 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246892
|
8.8 |
HIGH
Network
|
bigtreecms
|
bigtree_cms
|
BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename pa…
|
CWE-94
Code Injection
|
CVE-2017-9442
|
2024-11-21 12:36 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246893
|
5.4 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mi…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9441
|
2024-11-21 12:36 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246894
|
8.8 |
HIGH
Network
|
openbravo
|
openbravo_erp
|
Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code.
|
CWE-89
SQL Injection
|
CVE-2017-9437
|
2024-11-21 12:36 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246895
|
9.8 |
CRITICAL
Network
|
teampass
|
teampass
|
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
|
CWE-89
SQL Injection
|
CVE-2017-9436
|
2024-11-21 12:36 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246896
|
9.8 |
CRITICAL
Network
|
dolibarr
|
dolibarr
|
Dolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters).
|
CWE-89
SQL Injection
|
CVE-2017-9435
|
2024-11-21 12:36 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246897
|
5.3 |
MEDIUM
Network
|
cryptopp
|
crypto\+\+
|
Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9434
|
2024-11-21 12:36 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246898
|
9.8 |
CRITICAL
Network
|
dnstracer_project
|
dnstracer
|
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name ar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9430
|
2024-11-21 12:36 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246899
|
9.8 |
CRITICAL
Network
|
libmwaw_project
|
libmwaw
|
Document Liberation Project libmwaw before 2017-04-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the MsWrd1Parser::readFootnoteCorrespondance function in lib/MsWrd1P…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9433
|
2024-11-21 12:36 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246900
|
9.8 |
CRITICAL
Network
|
libstaroffice_project
|
libstaroffice
|
Document Liberation Project libstaroffice before 2017-04-07 has an out-of-bounds write caused by a stack-based buffer overflow related to the DatabaseName::read function in lib/StarWriterStruct.cxx.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-9432
|
2024-11-21 12:36 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|