|
250941
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
The function PdfPagesTree::GetPageNodeFromArray in PdfPageTree.cpp:464 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted PD…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-8054
|
2024-11-21 12:33 |
2017-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250942
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
PoDoFo 0.9.5 allows denial of service (infinite recursion and stack consumption) via a crafted PDF file in PoDoFo::PdfParser::ReadDocumentStructure (PdfParser.cpp).
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-8053
|
2024-11-21 12:33 |
2017-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250943
|
6.1 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 2.6.2974 allows XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8052
|
2024-11-21 12:33 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250944
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.
|
CWE-89
SQL Injection
|
CVE-2017-7991
|
2024-11-21 12:33 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250945
|
9.8 |
CRITICAL
Network
|
tenable
|
appliance
|
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote…
|
CWE-78
OS Command
|
CVE-2017-8051
|
2024-11-21 12:33 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250946
|
7.5 |
HIGH
Network
|
tenable
|
appliance
|
Tenable Appliance 4.4.0, and possibly prior, contains a flaw in the Web UI that allows for the unauthorized manipulation of the admin password.
|
NVD-CWE-noinfo
|
CVE-2017-8050
|
2024-11-21 12:33 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250947
|
6.5 |
MEDIUM
Network
|
podofo_project
|
podofo
|
The function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-7994
|
2024-11-21 12:33 |
2017-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250948
|
6.1 |
MEDIUM
Network
|
heartland_payment_systems
|
heartland-php
|
Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php v2.8.17 is vulnerable to a reflected XSS in examples/consumer-authentication/cruise.php via the URI, as demonstrated by the cavv pa…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7992
|
2024-11-21 12:33 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250949
|
8.8 |
HIGH
Network
|
wondercms
|
wondercms
|
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.
|
CWE-352
Origin Validation Error
|
CVE-2017-7951
|
2024-11-21 12:33 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250950
|
8.8 |
HIGH
Network
|
openmrs
|
openmrs_module_reporting
|
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageRepor…
|
CWE-352
Origin Validation Error
|
CVE-2017-7990
|
2024-11-21 12:33 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|