|
247931
|
7.0 |
HIGH
Local
|
modx php
|
modx_revolution php
|
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/i…
|
CWE-22
Path Traversal
|
CVE-2017-9067
|
2024-11-21 12:35 |
2017-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247932
|
8.6 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-9066
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247933
|
7.5 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
|
CWE-20
Improper Input Validation
|
CVE-2017-9065
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247934
|
8.8 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.
|
CWE-352
Origin Validation Error
|
CVE-2017-9064
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247935
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9063
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247936
|
8.6 |
HIGH
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
|
CWE-352 CWE-79 CWE-601
Origin Validation Error Cross-site Scripting Open Redirect
|
CVE-2017-9062
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247937
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filen…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9061
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247938
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The NFSv4 implementation in the Linux kernel through 4.11.1 allows local users to cause a denial of service (resource consumption) by leveraging improper channel callback shutdown when unmounting an …
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2017-9059
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247939
|
9.8 |
CRITICAL
Network
|
ytnef_project canonical
|
ytnef ubuntu_linux
|
In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9058
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247940
|
9.8 |
CRITICAL
Network
|
libdwarf_project
|
libdwarf
|
An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were not checked for being in bounds, leading to a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9055
|
2024-11-21 12:35 |
2017-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|