|
253441
|
7.5 |
HIGH
Network
|
gnu
|
binutils
|
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 4 due to NULL pointer dereferencing of _bfd_elf_large_com_section.…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-8394
|
2024-11-21 12:33 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253442
|
7.5 |
HIGH
Network
|
gnu
|
binutils
|
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcop…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-8393
|
2024-11-21 12:33 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253443
|
7.5 |
HIGH
Network
|
gnu
|
binutils
|
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-8392
|
2024-11-21 12:33 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253444
|
5.3 |
MEDIUM
Network
|
genixcms
|
genixcms
|
GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.
|
NVD-CWE-noinfo
|
CVE-2017-8388
|
2024-11-21 12:33 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253445
|
8.8 |
HIGH
Network
|
genixcms
|
genixcms
|
GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-8377
|
2024-11-21 12:33 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253446
|
5.4 |
MEDIUM
Network
|
genixcms
|
genixcms
|
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.
|
CWE-79
Cross-site Scripting
|
CVE-2017-8376
|
2024-11-21 12:33 |
2017-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253447
|
5.3 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2017-8385
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253448
|
6.1 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of …
|
CWE-79
Cross-site Scripting
|
CVE-2017-8384
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253449
|
5.3 |
MEDIUM
Network
|
craftcms
|
craft_cms
|
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
|
NVD-CWE-noinfo
|
CVE-2017-8383
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253450
|
9.8 |
CRITICAL
Network
|
podofo_project
|
podofo
|
Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspe…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-8378
|
2024-11-21 12:33 |
2017-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|