CVE-2017-1000000 to CVE-2017-1000999
64 CVEs with public proof-of-concept exploits.
- CVE-2017-10000021 PoCATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component…
- CVE-2017-10000061 PoCPlotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue.
- CVE-2017-10000271 PoCKoozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function…
- CVE-2017-100002810 PoCsOracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal…
- CVE-2017-10000291 PoCOracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible…
- CVE-2017-10000331 PoCWordpress Plugin Vospari Forms version < 1.4 is vulnerable to a reflected cross site scripting in the form submission resulting in…
- CVE-2017-10000371 PoCRVM automatically loads environment variables from files in $PWD resulting in command execution RVM vulnerable to command injection when…
- CVE-2017-10000381 PoCWordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the…
- CVE-2017-10000421 PoCMapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage…
- CVE-2017-10000431 PoCMapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain uncommon usage…
- CVE-2017-10000601 PoCEyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
- CVE-2017-10000721 PoCCreolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected…
- CVE-2017-10000751 PoCCreolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function
- CVE-2017-10000835 PoCsbackend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary…
- CVE-2017-100011212 PoCsLinux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data()…
- CVE-2017-100011724 PoCsA malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any…
- CVE-2017-10001192 PoCsOctober CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other…
- CVE-2017-10001361 PoCMahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being…
- CVE-2017-10001401 PoCMahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .xml…
- CVE-2017-10001471 PoCMahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF)…
- CVE-2017-10001631 PoCThe Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL…
- CVE-2017-10001706 PoCsjqueryFileTree 2.1.5 and older Directory Traversal
- CVE-2017-10001721 PoCCreolabs Gravity Version: 1.0 Use-After-Free Possible code execution. An example of a Heap-Use-After-Free after the 'sublexer' pointer has…
- CVE-2017-10001731 PoCCreolabs Gravity Version: 1.0 Heap Overflow Potential Code Execution. By creating a large loop whiling pushing data to a buffer, we can…
- CVE-2017-10001901 PoCSimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
- CVE-2017-10002181 PoCLightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code…
- CVE-2017-10002191 PoCnpm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user
- CVE-2017-10002241 PoCCSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin
- CVE-2017-10002251 PoCReflected XSS in Relevanssi Premium version 1.14.8 when using relevanssi_didyoumean() could allow unauthenticated attacker to do almost…
- CVE-2017-10002261 PoCStop User Enumeration 1.3.8 allows user enumeration via the REST API
- CVE-2017-10002271 PoCStored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin…
- CVE-2017-10002291 PoCInteger overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of…
- CVE-2017-10002501 PoCAll versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote…
- CVE-2017-10002519 PoCsThe native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are…
- CVE-2017-10002533 PoCsKEVLinux distributions that have not patched their long-term kernels with…
- CVE-2017-10002541 PoClibcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in…
- CVE-2017-10003538 PoCsKEVJenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An…
- CVE-2017-10003642 PoCsAn issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can…
- CVE-2017-10003663 PoCsglibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias,…
- CVE-2017-10003676 PoCsTodd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function…
- CVE-2017-10003681 PoCTodd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname()…
- CVE-2017-10003702 PoCsThe offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments…
- CVE-2017-10003713 PoCsThe offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of…
- CVE-2017-10003731 PoCThe OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that…
- CVE-2017-10003752 PoCsNetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily…
- CVE-2017-10003791 PoCThe Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is…
- CVE-2017-10004055 PoCsThe Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP…
- CVE-2017-10004081 PoCA memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable.…
- CVE-2017-10004091 PoCA buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable.…
- CVE-2017-10004181 PoCThe WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of…
- CVE-2017-10004271 PoCmarked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
- CVE-2017-10004321 PoCVanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
- CVE-2017-10004341 PoCWordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allows for a redirect…
- CVE-2017-10004371 PoCCreolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote code execution.
- CVE-2017-10004501 PoCIn opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer…
- CVE-2017-10004661 PoCInvoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result…
- CVE-2017-10004741 PoCSoyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php,…
- CVE-2017-10004752 PoCsFreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.
- CVE-2017-10004771 PoCXMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.
- CVE-2017-10004791 PoCpfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of…
- CVE-2017-100048613 PoCsKEVPrimetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
- CVE-2017-10004871 PoCPlexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
- CVE-2017-10004993 PoCsphpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is…
- CVE-2017-10006001 PoCWordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution.…