|
248851
|
6.1 |
MEDIUM
Network
|
netflix
|
security_monkey
|
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.
|
CWE-601
Open Redirect
|
CVE-2017-7266
|
2024-11-21 12:31 |
2017-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248852
|
7.8 |
HIGH
Local
|
artifex
|
mupdf
|
Use-after-free vulnerability in the fz_subsample_pixmap function in fitz/pixmap.c in Artifex MuPDF 1.10a allows remote attackers to cause a denial of service (application crash) or possibly have unsp…
|
CWE-416
Use After Free
|
CVE-2017-7264
|
2024-11-21 12:31 |
2017-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248853
|
7.8 |
HIGH
Local
|
potrace_project
|
potrace
|
The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-7263
|
2024-11-21 12:31 |
2017-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248854
|
5.5 |
MEDIUM
Local
|
amd
|
ryzen
|
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demo…
|
CWE-20
Improper Input Validation
|
CVE-2017-7262
|
2024-11-21 12:31 |
2017-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248855
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value of certain levels data, which allows local users to…
|
CWE-20
Improper Input Validation
|
CVE-2017-7261
|
2024-11-21 12:31 |
2017-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248856
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7257
|
2024-11-21 12:31 |
2017-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248857
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_summary parameter. Someone must login to conduct the attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7256
|
2024-11-21 12:31 |
2017-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248858
|
5.4 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the attack.
|
CWE-79
Cross-site Scripting
|
CVE-2017-7255
|
2024-11-21 12:31 |
2017-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248859
|
7.5 |
HIGH
Network
|
eclipse
|
tinydtls
|
Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-7243
|
2024-11-21 12:31 |
2017-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248860
|
7.5 |
HIGH
Network
|
miele_professional
|
pst10_webserver
|
An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefor…
|
CWE-22
Path Traversal
|
CVE-2017-7240
|
2024-11-21 12:31 |
2017-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|