|
257001
|
6.5 |
MEDIUM
Network
|
libzip debian
|
libzip debian_linux
|
The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-14107
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257002
|
7.8 |
HIGH
Local
|
aerohive
|
hivemanager_classic
|
HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive. An au…
|
CWE-20
Improper Input Validation
|
CVE-2017-14105
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257003
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering…
|
CWE-369
Divide By Zero
|
CVE-2017-14106
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257004
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote attackers to conduct …
|
CWE-416
Use After Free
|
CVE-2017-14103
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257005
|
7.8 |
HIGH
Local
|
mimedefang
|
mimedefang
|
MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account…
|
CWE-665
Improper Initialization
|
CVE-2017-14102
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257006
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.
|
CWE-89
SQL Injection
|
CVE-2017-14076
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257007
|
6.1 |
MEDIUM
Network
|
nexusphp
|
nexusphp
|
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14070
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257008
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.
|
CWE-89
SQL Injection
|
CVE-2017-14069
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257009
|
9.8 |
CRITICAL
Network
|
ruby-lang debian canonical redhat
|
ruby debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise…
|
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14064
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257010
|
7.5 |
HIGH
Network
|
asynchttpclient_project
|
async-http-client
|
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. S…
|
CWE-20
Improper Input Validation
|
CVE-2017-14063
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|