|
252941
|
7.5 |
HIGH
Network
|
apache
|
http_server
|
A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the server process.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-7659
|
2024-11-21 12:32 |
2017-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252942
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The brcmf_cfg80211_mgmt_tx function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.12.3 allows local users to cause a denial of service (buffer overflow a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7541
|
2024-11-21 12:32 |
2017-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252943
|
9.8 |
CRITICAL
Network
|
safemode_project
|
safemode
|
rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user doe…
|
NVD-CWE-noinfo
|
CVE-2017-7540
|
2024-11-21 12:32 |
2017-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252944
|
7.5 |
HIGH
Network
|
cygwin
|
cygwin
|
Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7523
|
2024-11-21 12:32 |
2017-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252945
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The ip6_find_1stfragopt function in net/ipv6/output_core.c in the Linux kernel through 4.12.3 allows local users to cause a denial of service (integer overflow and infinite loop) by leveraging the ab…
|
-
|
CVE-2017-7542
|
2024-11-21 12:32 |
2017-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252946
|
8.8 |
HIGH
Network
|
spice_project
|
spice
|
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server …
|
-
|
CVE-2017-7506
|
2024-11-21 12:32 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252947
|
6.5 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.x, course creators are able to change system default settings for courses.
|
CWE-269
Improper Privilege Management
|
CVE-2017-7532
|
2024-11-21 12:32 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252948
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.3, the course overview block reveals activities in hidden courses.
|
CWE-200
Information Exposure
|
CVE-2017-7531
|
2024-11-21 12:32 |
2017-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252949
|
7.5 |
HIGH
Network
|
apache
|
openmeetings
|
Apache OpenMeetings 1.0.0 updates user password in insecure manner.
|
NVD-CWE-noinfo
|
CVE-2017-7688
|
2024-11-21 12:32 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252950
|
5.3 |
MEDIUM
Network
|
apache
|
openmeetings
|
Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.
|
NVD-CWE-noinfo
|
CVE-2017-7685
|
2024-11-21 12:32 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|