|
251031
|
7.1 |
HIGH
Network
|
rapid7
|
metasploit
|
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build …
|
CWE-22
Path Traversal
|
CVE-2017-5228
|
2024-11-21 12:27 |
2017-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251032
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
The jpc_undo_roi function in libjasper/jpc/jpc_dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5504
|
2024-11-21 12:27 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251033
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
The dec_clnpass function in libjasper/jpc/jpc_t1dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impac…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-5503
|
2024-11-21 12:27 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251034
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
libjasper/jp2/jp2_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
|
NVD-CWE-noinfo
|
CVE-2017-5502
|
2024-11-21 12:27 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251035
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
Integer overflow in libjasper/jpc/jpc_tsfb.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5501
|
2024-11-21 12:27 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251036
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
|
NVD-CWE-noinfo
|
CVE-2017-5500
|
2024-11-21 12:27 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251037
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5499
|
2024-11-21 12:27 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251038
|
5.5 |
MEDIUM
Local
|
jasper_project
|
jasper
|
libjasper/include/jasper/jas_math.h in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
|
NVD-CWE-noinfo
|
CVE-2017-5498
|
2024-11-21 12:27 |
2017-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251039
|
9.8 |
CRITICAL
Network
|
tigervnc
|
tigervnc
|
Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer bound…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5581
|
2024-11-21 12:27 |
2017-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251040
|
9.8 |
CRITICAL
Network
|
opentext
|
documentum_d2
|
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons C…
|
CWE-20
Improper Input Validation
|
CVE-2017-5586
|
2024-11-21 12:27 |
2017-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|