|
249221
|
7.8 |
HIGH
Local
|
libraw
|
libraw
|
A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC fil…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6887
|
2024-11-21 12:30 |
2017-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249222
|
9.8 |
CRITICAL
Network
|
libraw
|
libraw
|
An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6886
|
2024-11-21 12:30 |
2017-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249223
|
9.8 |
CRITICAL
Network
|
flexerasoftware
|
flexnet_manager_suite
|
An error when handling certain external commands and services related to the FlexNet Inventory Agent and FlexNet Beacon of the Flexera Software FlexNet Manager Suite 2017 before 2017 R1 and 2014 R3 t…
|
NVD-CWE-noinfo
|
CVE-2017-6885
|
2024-11-21 12:30 |
2017-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249224
|
9.8 |
CRITICAL
Network
|
libraw
|
libraw-demosaic-pack-gpl2
|
A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a stack-based buffer …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6890
|
2024-11-21 12:30 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249225
|
9.8 |
CRITICAL
Network
|
libraw
|
libraw-demosaic-pack-gpl2
|
An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a heap-based buffer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-6889
|
2024-11-21 12:30 |
2017-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249226
|
4.9 |
MEDIUM
Network
|
siemens
|
simatic_wincc_\(tia_portal\) simatic_wincc simatic_wincc_runtime
|
A vulnerability was discovered in Siemens SIMATIC WinCC (V7.3 before Upd 11 and V7.4 before SP1), SIMATIC WinCC Runtime Professional (V13 before SP2 and V14 before SP1), SIMATIC WinCC (TIA Portal) Pr…
|
CWE-20
Improper Input Validation
|
CVE-2017-6867
|
2024-11-21 12:30 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249227
|
6.5 |
MEDIUM
Adjacent
|
siemens
|
sinaut_st7cc simatic_step_7_\(tia_portal\) simatic_winac_rtx_2010 simatic_wincc_\(tia_portal\) sinumerik_808d_programming_tool simatic_winac_rtx_f_2010 simatic_wincc_flexible_2008
|
A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET PC-Software (All versions < V14 SP1), SIMATIC PCS…
|
CWE-20
Improper Input Validation
|
CVE-2017-6865
|
2024-11-21 12:30 |
2017-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249228
|
7.8 |
HIGH
Local
|
gemalto
|
smartdiag_diagnosis_tool
|
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields. There may be a risk of local code execution with untrusted inpu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6953
|
2024-11-21 12:30 |
2017-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249229
|
8.8 |
HIGH
Network
|
xirrus
|
arrayos
|
SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2017-6557
|
2024-11-21 12:30 |
2017-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249230
|
5.3 |
MEDIUM
Network
|
cisco
|
unity_connection
|
A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attacker to access files in arbitrary locations on the filesystem of an affected devi…
|
CWE-22
Path Traversal
|
CVE-2017-6629
|
2024-11-21 12:30 |
2017-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|