|
252631
|
8.4 |
HIGH
Local
|
samsung
|
samsung_mobile
|
On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs…
|
CWE-20
Improper Input Validation
|
CVE-2017-18020
|
2024-11-21 12:19 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252632
|
7.1 |
HIGH
Local
|
k7computing
|
total_security
|
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a…
|
CWE-20
Improper Input Validation
|
CVE-2017-18019
|
2024-11-21 12:19 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252633
|
4.7 |
MEDIUM
Local
|
gnu
|
coreutils
|
In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify …
|
CWE-362
Race Condition
|
CVE-2017-18018
|
2024-11-21 12:19 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252634
|
9.8 |
CRITICAL
Network
|
linux debian arista f5 suse opensuse openstack canonical redhat
|
linux_kernel debian_linux eos arx linux_enterprise_server linux_enterprise_software_development_kit linux_enterprise_debuginfo linux_enterprise_desktop linux_enterprise_real_t…
|
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memor…
|
CWE-416
Use After Free
|
CVE-2017-18017
|
2024-11-21 12:19 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252635
|
6.1 |
MEDIUM
Network
|
wp-unit
|
share_this_image
|
The ILLID Share This Image plugin before 1.04 for WordPress has XSS via the sharer.php url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18015
|
2024-11-21 12:19 |
2018-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252636
|
6.5 |
MEDIUM
Network
|
libtiff
|
libtiff
|
In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-18013
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252637
|
6.1 |
MEDIUM
Network
|
z-url_preview_project
|
z-url_preview
|
The Z-URL Preview plugin 1.6.1 for WordPress has XSS via the class.zlinkpreview.php url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18012
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252638
|
6.1 |
MEDIUM
Network
|
clickbank
|
affiliate_ads_for_clickbank_products
|
The MyCBGenie Affiliate Ads for Clickbank Products plugin through 1.6 for WordPress has XSS via the text_ads_ajax.php border_color parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18011
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252639
|
6.1 |
MEDIUM
Network
|
e-goi
|
smart_marketing_sms_and_newsletters_forms
|
The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18010
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252640
|
7.5 |
HIGH
Network
|
opencv
|
opencv
|
In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfmt_hdr.cpp.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-18009
|
2024-11-21 12:19 |
2018-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|