|
247411
|
9.8 |
CRITICAL
Network
|
xmlsoft debian google
|
libxml2 debian_linux android
|
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD …
|
CWE-611
XXE
|
CVE-2017-7375
|
2024-11-21 12:31 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247412
|
8.8 |
HIGH
Network
|
vanderbilt
|
redcap
|
A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.
|
CWE-89
SQL Injection
|
CVE-2017-7351
|
2024-11-21 12:31 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247413
|
7.8 |
HIGH
Local
|
yandex
|
yandex_browser
|
Yandex Browser installer for Desktop before 17.4.1 has a DLL Hijacking Vulnerability because an untrusted search path is used for dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll or profapi.dll.
|
CWE-426
Untrusted Search Path
|
CVE-2017-7327
|
2024-11-21 12:31 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247414
|
7.5 |
HIGH
Network
|
yandex
|
yandex_browser
|
Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page
|
CWE-362
Race Condition
|
CVE-2017-7326
|
2024-11-21 12:31 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247415
|
7.5 |
HIGH
Network
|
yandex
|
yandex_browser
|
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.
|
CWE-20
Improper Input Validation
|
CVE-2017-7325
|
2024-11-21 12:31 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247416
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7163
|
2024-11-21 12:31 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247417
|
7.8 |
HIGH
Local
|
apple
|
iphone_os mac_os_x watchos tvos
|
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7162
|
2024-11-21 12:31 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247418
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOAcceleratorFamily" component. It allows attackers to execute arbitrary code in a privile…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7159
|
2024-11-21 12:31 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247419
|
6.5 |
MEDIUM
Network
|
apple
|
mac_os_x
|
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Screen Sharing Server" component. It allows attackers to obtain root privileges for readin…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7158
|
2024-11-21 12:31 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247420
|
8.8 |
HIGH
Network
|
apple canonical
|
iphone_os safari tvos icloud itunes ubuntu_linux webkit
|
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7160
|
2024-11-21 12:31 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|