|
249681
|
4.3 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
CSRF exists in BigTree CMS 4.2.16 with the value parameter to the admin/settings/update/ page. The Colophon can be changed.
|
CWE-352
Origin Validation Error
|
CVE-2017-6917
|
2024-11-21 12:30 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249682
|
4.3 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page. The Navigation Social can be changed.
|
CWE-352
Origin Validation Error
|
CVE-2017-6916
|
2024-11-21 12:30 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249683
|
4.3 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
CSRF exists in BigTree CMS 4.1.18 with the colophon parameter to the admin/settings/update/ page. The Colophon can be changed.
|
CWE-352
Origin Validation Error
|
CVE-2017-6915
|
2024-11-21 12:30 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249684
|
7.1 |
HIGH
Network
|
bigtreecms
|
bigtree_cms
|
CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page. A user can be deleted.
|
CWE-352
Origin Validation Error
|
CVE-2017-6914
|
2024-11-21 12:30 |
2017-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249685
|
7.8 |
HIGH
Local
|
jasper_project
|
jasper
|
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote attackers to have unspecified impact via a crafted image.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6852
|
2024-11-21 12:30 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249686
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-6851
|
2024-11-21 12:30 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249687
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6850
|
2024-11-21 12:30 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249688
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
The PoDoFo::PdfColorGray::~PdfColorGray function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6849
|
2024-11-21 12:30 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249689
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
The PoDoFo::PdfXObject::PdfXObject function in PdfXObject.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6848
|
2024-11-21 12:30 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249690
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-6847
|
2024-11-21 12:30 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|