|
256501
|
5.3 |
MEDIUM
Network
|
argosoft
|
mini_mail_server
|
Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an in…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-15223
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256502
|
9.8 |
CRITICAL
Network
|
nftp_project
|
nftp
|
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-15222
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256503
|
6.5 |
MEDIUM
Network
|
ffmpeg
|
ffmpeg
|
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.
|
CWE-415
Double Free
|
CVE-2017-15186
|
2024-11-21 12:14 |
2017-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256504
|
9.8 |
CRITICAL
Network
|
phpsugar
|
php_melody
|
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
|
CWE-89
SQL Injection
|
CVE-2017-15081
|
2024-11-21 12:14 |
2017-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256505
|
9.8 |
CRITICAL
Network
|
osticket
|
osticket
|
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15580
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256506
|
7.8 |
HIGH
Local
|
idemia
|
mso_1300_firmware
|
The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via …
|
NVD-CWE-noinfo
|
CVE-2017-15567
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256507
|
9.8 |
CRITICAL
Network
|
softwarepublico
|
e-sic
|
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).
|
CWE-89
SQL Injection
|
CVE-2017-15381
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256508
|
6.1 |
MEDIUM
Network
|
softwarepublico
|
e-sic
|
XSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the requester's registration area) via the nome parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15380
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256509
|
9.8 |
CRITICAL
Network
|
softwarepublico
|
e-sic
|
An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.
|
CWE-89
SQL Injection
|
CVE-2017-15379
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256510
|
8.8 |
HIGH
Network
|
softwarepublico
|
e-sic
|
SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).
|
CWE-89
SQL Injection
|
CVE-2017-15378
|
2024-11-21 12:14 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|