|
247111
|
7.8 |
HIGH
Local
|
google
|
android
|
When an atomic commit is issued on a writeback panel with a NULL output_layer parameter in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-03, a NULL pointer dereference may poten…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-9692
|
2024-11-21 12:36 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247112
|
4.7 |
MEDIUM
Local
|
google
|
android
|
There is a race condition in Android for MSM, Firefox OS for MSM, and QRD Android that allows to access to already free'd memory in the debug message output functionality contained within the mobicor…
|
CWE-362
Race Condition
|
CVE-2017-9691
|
2024-11-21 12:36 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247113
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel memory address is passed from userspace through iris…
|
CWE-200
Information Exposure
|
CVE-2017-9681
|
2024-11-21 12:36 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247114
|
6.1 |
MEDIUM
Network
|
projectsend
|
projectsend
|
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the D…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9786
|
2024-11-21 12:36 |
2018-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247115
|
6.1 |
MEDIUM
Network
|
projectsend
|
projectsend
|
Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the D…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9783
|
2024-11-21 12:36 |
2018-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247116
|
7.5 |
HIGH
Network
|
parallels
|
remote_application_server
|
In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Ga…
|
CWE-22
Path Traversal
|
CVE-2017-9447
|
2024-11-21 12:36 |
2018-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247117
|
9.8 |
CRITICAL
Network
|
facetag_project
|
facetag
|
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.
|
CWE-89
SQL Injection
|
CVE-2017-9426
|
2024-11-21 12:36 |
2018-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247118
|
6.1 |
MEDIUM
Network
|
facetag_project
|
facetag
|
The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9425
|
2024-11-21 12:36 |
2018-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247119
|
8.8 |
HIGH
Network
|
subsonic
|
subsonic
|
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that con…
|
CWE-352
Origin Validation Error
|
CVE-2017-9414
|
2024-11-21 12:36 |
2018-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247120
|
5.4 |
MEDIUM
Network
|
atlassian
|
activity_streams
|
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are ad…
|
CWE-862
Missing Authorization
|
CVE-2017-9513
|
2024-11-21 12:36 |
2018-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|