|
256201
|
7.5 |
HIGH
Network
|
writediary
|
diary_with_lock
|
In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obta…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-15582
|
2024-11-21 12:14 |
2017-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256202
|
7.5 |
HIGH
Network
|
writediary
|
diary_with_lock
|
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2017-15581
|
2024-11-21 12:14 |
2017-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256203
|
9.8 |
CRITICAL
Network
|
ndocsoftware
|
ndoc
|
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-15366
|
2024-11-21 12:14 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256204
|
3.3 |
LOW
Local
|
gluster
|
glusterfs
|
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15096
|
2024-11-21 12:14 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256205
|
5.3 |
MEDIUM
Network
|
argosoft
|
mini_mail_server
|
Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an in…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-15223
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256206
|
9.8 |
CRITICAL
Network
|
nftp_project
|
nftp
|
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-15222
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256207
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
|
CWE-415
Double Free
|
CVE-2017-15186
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256208
|
9.8 |
CRITICAL
Network
|
phpsugar
|
php_melody
|
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
|
CWE-89
SQL Injection
|
CVE-2017-15081
|
2024-11-21 12:14 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256209
|
9.8 |
CRITICAL
Network
|
osticket
|
osticket
|
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15580
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256210
|
7.8 |
HIGH
Local
|
idemia
|
mso_1300_firmware
|
The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via …
|
NVD-CWE-noinfo
|
CVE-2017-15567
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|