|
255451
|
9.8 |
CRITICAL
Network
|
osticket
|
osticket
|
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.
|
CWE-89
SQL Injection
|
CVE-2017-14396
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255452
|
8.8 |
HIGH
Network
|
libraw
|
libraw
|
LibRaw before 0.18.4 has a heap-based Buffer Overflow in the processCanonCameraInfo function via a crafted file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14348
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255453
|
6.1 |
MEDIUM
Network
|
nexusphp_project
|
nexusphp
|
NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14347
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255454
|
9.8 |
CRITICAL
Network
|
blog_project
|
blog
|
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-14346
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255455
|
9.8 |
CRITICAL
Network
|
blog_project
|
blog
|
SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php.
|
CWE-89
SQL Injection
|
CVE-2017-14345
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255456
|
7.8 |
HIGH
Local
|
jungo
|
windriver
|
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system i…
|
CWE-20
Improper Input Validation
|
CVE-2017-14344
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255457
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.6-6 has a memory leak vulnerability in ReadXCFImage in coders/xcf.c via a crafted xcf image file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-14343
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255458
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c via a crafted wpg image file.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-14342
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255459
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-14341
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255460
|
8.1 |
HIGH
Network
|
misp-project
|
misp
|
When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate…
|
CWE-287
Improper Authentication
|
CVE-2017-14337
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|