|
248001
|
6.8 |
MEDIUM
Physics
|
libmtp_project
|
libmtp
|
An integer overflow vulnerability in ptp-pack.c (ptp_unpack_OPL function) of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe rem…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-9832
|
2024-11-21 12:36 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248002
|
6.8 |
MEDIUM
Physics
|
libmtp_project
|
libmtp
|
An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-9831
|
2024-11-21 12:36 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248003
|
7.5 |
HIGH
Network
|
vivotek
|
network_camera_ib8369_firmware network_camera_fd8164_firmware network_camera_fd816ba_firmware
|
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a craf…
|
CWE-22
Path Traversal
|
CVE-2017-9829
|
2024-11-21 12:36 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248004
|
9.8 |
CRITICAL
Network
|
ocaml
|
ocaml
|
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_N…
|
NVD-CWE-noinfo
|
CVE-2017-9772
|
2024-11-21 12:36 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248005
|
9.8 |
CRITICAL
Network
|
vivotek
|
network_camera_ib8369_firmware network_camera_fd8164_firmware network_camera_fd816ba_firmware
|
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root …
|
CWE-78
OS Command
|
CVE-2017-9828
|
2024-11-21 12:36 |
2017-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248006
|
7.8 |
HIGH
Local
|
freedesktop debian redhat
|
poppler debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_server…
|
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspe…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-9776
|
2024-11-21 12:36 |
2017-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248007
|
6.5 |
MEDIUM
Network
|
freedesktop debian redhat
|
poppler debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_server…
|
Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9775
|
2024-11-21 12:36 |
2017-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248008
|
9.8 |
CRITICAL
Network
|
ideablade
|
breeze.server.net
|
IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-9424
|
2024-11-21 12:36 |
2017-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248009
|
6.5 |
MEDIUM
Network
|
libtiff canonical
|
libtiff ubuntu_linux
|
In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-9815
|
2024-11-21 12:36 |
2017-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248010
|
9.8 |
CRITICAL
Network
|
openwebif_project
|
openwebif
|
An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/controllers/models/config.py" performs an eval() call on the contents of the "key…
|
CWE-94
Code Injection
|
CVE-2017-9807
|
2024-11-21 12:36 |
2017-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|