|
255441
|
5.5 |
MEDIUM
Local
|
mp3gain
|
mp3gain
|
A stack-based buffer over-read was discovered in filterYule in gain_analysis.c in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to remote denial of service.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-14407
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255442
|
5.5 |
MEDIUM
Local
|
mp3gain
|
mp3gain
|
A NULL pointer dereference was discovered in sync_buffer in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes a segmentation fault and application crash, which lead…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14406
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255443
|
7.2 |
HIGH
Network
|
eyesofnetwork
|
eyesofnetwork
|
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to module/admin_device/index.php.
|
CWE-78
OS Command
|
CVE-2017-14405
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255444
|
7.5 |
HIGH
Network
|
eyesofnetwork
|
eyesofnetwork
|
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows local file inclusion via the tool_list parameter (aka the url_tool variable) to module/tool_all/select_tool.php, as demonstrated by a tool_li…
|
CWE-200
Information Exposure
|
CVE-2017-14404
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255445
|
9.8 |
CRITICAL
Network
|
eyesofnetwork
|
eyesofnetwork
|
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php.
|
CWE-89
SQL Injection
|
CVE-2017-14403
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255446
|
9.8 |
CRITICAL
Network
|
eyesofnetwork
|
eyesofnetwork
|
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT CREATION" section, related to lack of input v…
|
CWE-89
SQL Injection
|
CVE-2017-14402
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255447
|
9.8 |
CRITICAL
Network
|
eyesofnetwork
|
eyesofnetwork
|
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT UPDATE" section.
|
CWE-89
SQL Injection
|
CVE-2017-14401
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255448
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.7-1 Q16, the PersistPixelCache function in magick/cache.c mishandles the pixel cache nexus, which allows remote attackers to cause a denial of service (NULL pointer dereference in …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14400
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255449
|
8.8 |
HIGH
Network
|
blackcat-cms
|
blackcat_cms
|
In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-14399
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255450
|
9.8 |
CRITICAL
Network
|
anydesk
|
anydesk
|
AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability.
|
CWE-74
Injection
|
CVE-2017-14397
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|