|
247171
|
7.8 |
HIGH
Local
|
lame_project
|
lame
|
The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buffer overflow and ap…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9871
|
2024-11-21 12:37 |
2017-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247172
|
5.5 |
MEDIUM
Local
|
lame_project
|
lame
|
The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application c…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9870
|
2024-11-21 12:37 |
2017-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247173
|
5.5 |
MEDIUM
Local
|
lame_project
|
lame
|
The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application cr…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9869
|
2024-11-21 12:37 |
2017-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247174
|
5.5 |
MEDIUM
Local
|
eclipse debian
|
mosquitto debian_linux
|
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
|
CWE-200
Information Exposure
|
CVE-2017-9868
|
2024-11-21 12:37 |
2017-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247175
|
5.5 |
MEDIUM
Local
|
freedesktop debian
|
poppler debian_linux
|
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF doc…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9865
|
2024-11-21 12:37 |
2017-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247176
|
9.8 |
CRITICAL
Network
|
bmc
|
server_automation
|
BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.
|
CWE-863
Incorrect Authorization
|
CVE-2017-9453
|
2024-11-21 12:36 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247177
|
8.8 |
HIGH
Network
|
getvera
|
veraedge_firmware veralite_firmware
|
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides UPnP services that are available on port 3480 and can also be accessed via port 80 using the url "/po…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9392
|
2024-11-21 12:36 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247178
|
8.8 |
HIGH
Network
|
getvera
|
veraedge_firmware veralite_firmware
|
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides UPnP services that are available on port 3480 and can also be accessed via port 80 using the url "/po…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9391
|
2024-11-21 12:36 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247179
|
6.1 |
MEDIUM
Network
|
getvera
|
veraedge_firmware veralite_firmware
|
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a shell script called connect.sh which is supposed to return a specific cookie for the user when the …
|
CWE-79
Cross-site Scripting
|
CVE-2017-9390
|
2024-11-21 12:36 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247180
|
8.8 |
HIGH
Network
|
getvera
|
veraedge_firmware veralite_firmware
|
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface that allows a user to manage the device. As a part of the functionality the devi…
|
CWE-287
Improper Authentication
|
CVE-2017-9389
|
2024-11-21 12:36 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|