|
248021
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of specific HTML attributes leads to XSS vulnerabilities in various components.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7986
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248022
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering of multibyte characters leads to XSS vulnerabilities in various components.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7985
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248023
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate filtering leads to XSS in the template manager component.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7984
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248024
|
5.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! 1.5.0 through 3.6.5 (fixed in 3.7.0), mail sent using the JMail API leaked the used PHPMailer version in the mail headers.
|
CWE-200
Information Exposure
|
CVE-2017-7983
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248025
|
10.0 |
CRITICAL
Network
|
modified-shop
|
modified_ecommerce_shopsoftware
|
www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php.
|
CWE-611
XXE
|
CVE-2017-8110
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248026
|
7.8 |
HIGH
Local
|
saltstack
|
salt
|
The salt-ssh minion code in SaltStack Salt 2016.11 before 2016.11.4 copied over configuration from the Salt Master without adjusting permissions, which might leak credentials to local attackers on co…
|
CWE-200
Information Exposure
|
CVE-2017-8109
|
2024-11-21 12:33 |
2017-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248027
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) v…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-8106
|
2024-11-21 12:33 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248028
|
9.8 |
CRITICAL
Network
|
freetype debian
|
freetype debian_linux
|
FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-8105
|
2024-11-21 12:33 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248029
|
5.3 |
MEDIUM
Network
|
mybb
|
mybb
|
In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
|
CWE-22
Path Traversal
|
CVE-2017-8104
|
2024-11-21 12:33 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248030
|
6.1 |
MEDIUM
Network
|
mybb
|
mybb
|
In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8103
|
2024-11-21 12:33 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|