|
247201
|
9.8 |
CRITICAL
Network
|
facetag_project
|
facetag
|
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.
|
CWE-89
SQL Injection
|
CVE-2017-9426
|
2024-11-21 12:36 |
2018-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247202
|
6.1 |
MEDIUM
Network
|
facetag_project
|
facetag
|
The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9425
|
2024-11-21 12:36 |
2018-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247203
|
8.8 |
HIGH
Network
|
subsonic
|
subsonic
|
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that con…
|
CWE-352
Origin Validation Error
|
CVE-2017-9414
|
2024-11-21 12:36 |
2018-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247204
|
5.4 |
MEDIUM
Network
|
atlassian
|
activity_streams
|
Several rest inline action resources of Atlassian Activity Streams before version 6.3.0 allows remote authenticated attackers to watch any Confluence page & receive notifications when comments are ad…
|
CWE-862
Missing Authorization
|
CVE-2017-9513
|
2024-11-21 12:36 |
2018-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247205
|
7.5 |
HIGH
Network
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, if userspace provides a too-large IE length in wlan_hdd_cfg80211_set_ie, a buffer over-…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9712
|
2024-11-21 12:36 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247206
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, concurrent rx notifications and read() operations in the G-Link PKT driver can result i…
|
CWE-415
Double Free
|
CVE-2017-9705
|
2024-11-21 12:36 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247207
|
7.8 |
HIGH
Local
|
google
|
android
|
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a specially-crafted HDMI CEC message can be used to cause stack memory corruption.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9689
|
2024-11-21 12:36 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247208
|
5.3 |
MEDIUM
Network
|
apache
|
geode
|
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind p…
|
CWE-200
Information Exposure
|
CVE-2017-9796
|
2024-11-21 12:36 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247209
|
7.5 |
HIGH
Network
|
apache
|
geode
|
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries that allow read and write access to …
|
CWE-200
Information Exposure
|
CVE-2017-9795
|
2024-11-21 12:36 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247210
|
7.5 |
HIGH
Network
|
gm
|
shanghai_onstar
|
An Cleartext Storage of Sensitive Information issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow a remot…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2017-9663
|
2024-11-21 12:36 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|