|
250081
|
7.8 |
HIGH
Local
|
artifex
|
mujs
|
An issue was discovered in Artifex Software, Inc. MuJS before 8f62ea10a0af68e56d5c00720523ebcba13c2e6a. The MakeDay function in jsdate.c does not validate the month, leading to an integer overflow wh…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5628
|
2024-11-21 12:28 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250082
|
7.8 |
HIGH
Local
|
artifex
|
mujs
|
An issue was discovered in Artifex Software, Inc. MuJS before 4006739a28367c708dea19aeb19b8a1a9326ce08. The jsR_setproperty function in jsrun.c lacks a check for a negative array length. This leads t…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5627
|
2024-11-21 12:28 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250083
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
Cross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before 4.7.2 allows remote attackers to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5612
|
2024-11-21 12:28 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250084
|
9.8 |
CRITICAL
Network
|
wordpress debian oracle
|
wordpress debian_linux data_integrator
|
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected…
|
CWE-89
SQL Injection
|
CVE-2017-5611
|
2024-11-21 12:28 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250085
|
5.3 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypas…
|
CWE-200
Information Exposure
|
CVE-2017-5610
|
2024-11-21 12:28 |
2017-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250086
|
8.8 |
HIGH
Network
|
s9y
|
serendipity
|
SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter.
|
CWE-89
SQL Injection
|
CVE-2017-5609
|
2024-11-21 12:28 |
2017-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250087
|
7.7 |
HIGH
Network
|
rapid7
|
insightvm
|
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a vir…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2017-5242
|
2024-11-21 12:27 |
2023-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250088
|
8.8 |
HIGH
Local
|
linux netapp
|
linux_kernel cloud_backup h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h700e_firmware h410s_firmware
|
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
|
CWE-20
Improper Input Validation
|
CVE-2017-5123
|
2024-11-21 12:27 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250089
|
7.8 |
HIGH
Local
|
icoutils_project canonical debian opensuse
|
icoutils ubuntu_linux debian_linux leap opensuse
|
Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a craft…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5331
|
2024-11-21 12:27 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250090
|
7.8 |
HIGH
Local
|
icoutils_project redhat canonical debian opensuse
|
icoutils enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_server_eus ubuntu_linux
|
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitr…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5333
|
2024-11-21 12:27 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|