|
256811
|
9.8 |
CRITICAL
Network
|
digium
|
asterisk certified_asterisk
|
In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. Th…
|
CWE-78
OS Command
|
CVE-2017-14100
|
2024-11-21 12:12 |
2017-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256812
|
7.5 |
HIGH
Network
|
digium
|
asterisk certified_asterisk
|
In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data di…
|
CWE-200
Information Exposure
|
CVE-2017-14099
|
2024-11-21 12:12 |
2017-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256813
|
7.5 |
HIGH
Network
|
digium
|
asterisk
|
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.
|
CWE-20
Improper Input Validation
|
CVE-2017-14098
|
2024-11-21 12:12 |
2017-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256814
|
7.5 |
HIGH
Network
|
netapp
|
oncommand_unified_manager_for_clustered_data_ontap
|
NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, which makes it easier for remote attackers to captur…
|
CWE-200
Information Exposure
|
CVE-2017-14053
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256815
|
6.5 |
MEDIUM
Network
|
libzip debian
|
libzip debian_linux
|
The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-14107
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256816
|
7.8 |
HIGH
Local
|
aerohive
|
hivemanager_classic
|
HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive. An au…
|
CWE-20
Improper Input Validation
|
CVE-2017-14105
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256817
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering…
|
CWE-369
Divide By Zero
|
CVE-2017-14106
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256818
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote attackers to conduct …
|
CWE-416
Use After Free
|
CVE-2017-14103
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256819
|
7.8 |
HIGH
Local
|
mimedefang
|
mimedefang
|
MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account…
|
CWE-665
Improper Initialization
|
CVE-2017-14102
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256820
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.
|
CWE-89
SQL Injection
|
CVE-2017-14076
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|