|
255381
|
9.8 |
CRITICAL
Network
|
kaltura
|
kaltura_server
|
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to bypass an intended protection mechanism and cons…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-14143
|
2024-11-21 12:12 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255382
|
6.1 |
MEDIUM
Network
|
kaltura
|
kaltura_server
|
Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) partnerId or (2) playerVersion parameter to serv…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14142
|
2024-11-21 12:12 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255383
|
7.2 |
HIGH
Network
|
kaltura
|
kaltura_server
|
The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a craft…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-14141
|
2024-11-21 12:12 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255384
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.7-0 has a memory exhaustion issue in ReadSUNImage in coders/sun.c.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-14531
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255385
|
8.0 |
HIGH
Network
|
crony_cronjob_manager_project
|
crony_cronjob_manager
|
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.
|
CWE-352
Origin Validation Error
|
CVE-2017-14530
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255386
|
5.5 |
MEDIUM
Local
|
gnu
|
binutils
|
The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles HintName vector entries, which allows remote attack…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-14529
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255387
|
6.5 |
MEDIUM
Network
|
imagemagick debian
|
imagemagick debian_linux
|
The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply that data validation has occurred, which allows re…
|
CWE-416
Use After Free
|
CVE-2017-14528
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255388
|
7.8 |
HIGH
Local
|
freedesktop
|
poppler
|
In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.
|
CWE-20
Improper Input Validation
|
CVE-2017-14520
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255389
|
7.5 |
HIGH
Network
|
freedesktop
|
poppler
|
In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx::doShowText calls (…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-14519
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255390
|
7.8 |
HIGH
Local
|
freedesktop
|
poppler
|
In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.
|
CWE-20
Improper Input Validation
|
CVE-2017-14518
|
2024-11-21 12:12 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|