|
248081
|
5.5 |
MEDIUM
Local
|
long_range_zip_project
|
long_range_zip
|
The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive.
|
CWE-369
Divide By Zero
|
CVE-2017-8842
|
2024-11-21 12:34 |
2017-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248082
|
6.1 |
MEDIUM
Network
|
zen-cart
|
zen_cart
|
Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest…
|
CWE-79
Cross-site Scripting
|
CVE-2017-8833
|
2024-11-21 12:34 |
2017-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248083
|
6.1 |
MEDIUM
Network
|
allen_disk_project
|
allen_disk
|
Allen Disk 1.6 has XSS in the id parameter to downfile.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8832
|
2024-11-21 12:34 |
2017-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248084
|
6.4 |
MEDIUM
Physics
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly hav…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-8831
|
2024-11-21 12:34 |
2017-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248085
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.5-6, the ReadBMPImage function in bmp.c:1379 allows attackers to cause a denial of service (memory leak) via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-8830
|
2024-11-21 12:34 |
2017-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248086
|
7.8 |
HIGH
Local
|
debian
|
lintian
|
Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with a crafted YAML file.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-8829
|
2024-11-21 12:34 |
2017-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248087
|
9.1 |
CRITICAL
Network
|
genixcms
|
genixcms
|
forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks vi…
|
CWE-287
Improper Authentication
|
CVE-2017-8827
|
2024-11-21 12:34 |
2017-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248088
|
7.5 |
HIGH
Network
|
gnu
|
glibc
|
The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-8804
|
2024-11-21 12:34 |
2017-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248089
|
6.1 |
MEDIUM
Network
|
trendmicro
|
officescan
|
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8801
|
2024-11-21 12:34 |
2017-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248090
|
9.8 |
CRITICAL
Network
|
irods
|
irods
|
Untrusted input execution via igetwild in all iRODS versions before 4.1.11 and 4.2.1 allows other iRODS users (potentially anonymous) to execute remote shell commands via iRODS virtual pathnames. To …
|
CWE-78
OS Command
|
CVE-2017-8799
|
2024-11-21 12:34 |
2017-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|