|
249231
|
5.5 |
MEDIUM
Local
|
entropymine
|
imageworsener
|
The iwgif_record_pixel function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-7453
|
2024-11-21 12:31 |
2017-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249232
|
5.5 |
MEDIUM
Local
|
entropymine
|
imageworsener
|
The iwbmp_read_info_header function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-7452
|
2024-11-21 12:31 |
2017-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249233
|
9.8 |
CRITICAL
Network
|
airtame
|
hdmi_dongle_firmware
|
AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. It is possible to extract all information including the Wi-Fi password, reboot,…
|
CWE-287
Improper Authentication
|
CVE-2017-7450
|
2024-11-21 12:31 |
2017-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249234
|
5.5 |
MEDIUM
Local
|
dropbox
|
lepton
|
The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a…
|
CWE-369
Divide By Zero
|
CVE-2017-7448
|
2024-11-21 12:31 |
2017-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249235
|
8.8 |
HIGH
Network
|
helpdezk
|
helpdezk
|
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
|
CWE-352
Origin Validation Error
|
CVE-2017-7447
|
2024-11-21 12:31 |
2017-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249236
|
8.8 |
HIGH
Network
|
helpdezk
|
helpdezk
|
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
|
CWE-352
Origin Validation Error
|
CVE-2017-7446
|
2024-11-21 12:31 |
2017-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249237
|
7.8 |
HIGH
Local
|
veritas
|
system_recovery
|
In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker has write access to the directory from which the product is executed.
|
NVD-CWE-noinfo
|
CVE-2017-7444
|
2024-11-21 12:31 |
2017-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249238
|
6.1 |
MEDIUM
Network
|
apt-cacher_project apt-cacher-ng_project
|
apt-cacher apt-cacher-ng
|
apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression.
|
CWE-113
HTTP Response Splitting
|
CVE-2017-7443
|
2024-11-21 12:31 |
2017-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249239
|
7.3 |
HIGH
Local
|
lightdm_project canonical
|
lightdm ubuntu_linux
|
In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user …
|
CWE-22
Path Traversal
|
CVE-2017-7358
|
2024-11-21 12:31 |
2017-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249240
|
6.1 |
MEDIUM
Network
|
djangoproject
|
django
|
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an ope…
|
CWE-601
Open Redirect
|
CVE-2017-7234
|
2024-11-21 12:31 |
2017-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|