|
256441
|
8.8 |
HIGH
Network
|
intelliants
|
subrion_cms
|
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.
|
CWE-352
Origin Validation Error
|
CVE-2017-6066
|
2024-11-21 12:29 |
2017-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256442
|
8.8 |
HIGH
Network
|
eonweb_project
|
eonweb
|
EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3…
|
CWE-78
OS Command
|
CVE-2017-6087
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256443
|
8.8 |
HIGH
Network
|
firebirdsql
|
firebird
|
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.
|
CWE-862
Missing Authorization
|
CVE-2017-6369
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256444
|
5.9 |
MEDIUM
Network
|
apparmor canonical
|
apparmor ubuntu_touch ubuntu_core
|
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have …
|
CWE-269
Improper Privilege Management
|
CVE-2017-6507
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256445
|
9.8 |
CRITICAL
Network
|
microsoft
|
skype
|
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dl…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-6517
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256446
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2017-6361
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256447
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2017-6360
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256448
|
9.8 |
CRITICAL
Network
|
qnap
|
qts
|
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2017-6359
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256449
|
7.8 |
HIGH
Local
|
apng_disassembler_project
|
apng_disassembler
|
Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-6191
|
2024-11-21 12:29 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256450
|
6.7 |
MEDIUM
Local
|
avira
|
internet_security_suite free_security_suite total_security_suite optimization_suite
|
Code injection vulnerability in Avira Total Security Suite 15.0 (and earlier), Optimization Suite 15.0 (and earlier), Internet Security Suite 15.0 (and earlier), and Free Security Suite 15.0 (and ear…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-6417
|
2024-11-21 12:29 |
2017-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|