|
257211
|
8.8 |
HIGH
Network
|
blackcat-cms
|
blackcat_cms
|
BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addons/ajax_create.php. NOTE: this can be exploited via…
|
CWE-352
Origin Validation Error
|
CVE-2017-14048
|
2024-11-21 12:12 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257212
|
6.5 |
MEDIUM
Network
|
graphicsmagick
|
graphicsmagick
|
A memory allocation failure was discovered in the ReadPNMImage function in coders/pnm.c in GraphicsMagick 1.3.26. The vulnerability causes a big memory allocation, which may lead to remote denial of …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14042
|
2024-11-21 12:12 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257213
|
8.8 |
HIGH
Network
|
uclouvain debian
|
openjpeg debian_linux
|
A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of ser…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-14041
|
2024-11-21 12:12 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257214
|
8.8 |
HIGH
Network
|
uclouvain debian
|
openjpeg debian_linux
|
An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspec…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-14040
|
2024-11-21 12:12 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257215
|
8.8 |
HIGH
Network
|
uclouvain debian
|
openjpeg debian_linux
|
A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denia…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-14039
|
2024-11-21 12:12 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257216
|
6.1 |
MEDIUM
Network
|
crushftp
|
crushftp
|
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
|
CWE-601
Open Redirect
|
CVE-2017-14038
|
2024-11-21 12:12 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257217
|
6.1 |
MEDIUM
Network
|
crushftp
|
crushftp
|
CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.
|
CWE-93
CRLF Injection
|
CVE-2017-14037
|
2024-11-21 12:12 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257218
|
6.1 |
MEDIUM
Network
|
crushftp
|
crushftp
|
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14036
|
2024-11-21 12:12 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257219
|
9.8 |
CRITICAL
Network
|
crushftp
|
crushftp
|
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-14035
|
2024-11-21 12:12 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257220
|
8.1 |
HIGH
Network
|
arm
|
mbed_tls
|
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates…
|
CWE-287
Improper Authentication
|
CVE-2017-14032
|
2024-11-21 12:12 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|