|
247431
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The _bfd_vms_slurp_etir function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9745
|
2024-11-21 12:36 |
2017-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247432
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The sh_elf_set_mach_from_flags function in bfd/elf32-sh.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9744
|
2024-11-21 12:36 |
2017-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247433
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The print_insn_score32 function in opcodes/score7-dis.c:552 in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecif…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9743
|
2024-11-21 12:36 |
2017-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247434
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9742
|
2024-11-21 12:36 |
2017-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247435
|
9.8 |
CRITICAL
Network
|
projectsend
|
projectsend
|
install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.
|
CWE-20
Improper Input Validation
|
CVE-2017-9741
|
2024-11-21 12:36 |
2017-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247436
|
6.1 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via the description parameter in an addgroup action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9668
|
2024-11-21 12:36 |
2017-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247437
|
9.8 |
CRITICAL
Network
|
spip
|
spip
|
SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution.
|
CWE-78
OS Command
|
CVE-2017-9736
|
2024-11-21 12:36 |
2017-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247438
|
5.5 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and Q…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-9503
|
2024-11-21 12:36 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247439
|
7.5 |
HIGH
Network
|
eclipse debian oracle
|
jetty debian_linux retail_xstore_point_of_service hospitality_guest_access enterprise_manager_base_platform rest_data_services communications_cloud_native_core_policy
|
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect p…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2017-9735
|
2024-11-21 12:36 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247440
|
7.5 |
HIGH
Network
|
yocto_project
|
yp_core-pyro
|
In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive information by reading a URL in a Source entry in an ipk p…
|
CWE-200
Information Exposure
|
CVE-2017-9731
|
2024-11-21 12:36 |
2017-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|