CVE-2017-14000 to CVE-2017-14999
224 CVEs with public proof-of-concept exploits.
- CVE-2017-140162 PoCsA Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper…
- CVE-2017-140341 PoCThe restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.7 and other products, miscalculates a memcpy…
- CVE-2017-140421 PoCA memory allocation failure was discovered in the ReadPNMImage function in coders/pnm.c in GraphicsMagick 1.3.26. The vulnerability causes…
- CVE-2017-140641 PoCRuby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies…
- CVE-2017-140752 PoCsThis vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the…
- CVE-2017-140833 PoCsA vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to download the…
- CVE-2017-140841 PoCA potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary…
- CVE-2017-140853 PoCsInformation disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan…
- CVE-2017-140862 PoCsPre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can…
- CVE-2017-140874 PoCsA Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header,…
- CVE-2017-140893 PoCsAn Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can…
- CVE-2017-140901 PoCA vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.
- CVE-2017-140911 PoCA vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature -…
- CVE-2017-140921 PoCThe absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit…
- CVE-2017-140931 PoCThe Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 are vulnerable to cross site scripting (XSS) attacks.
- CVE-2017-140942 PoCsA vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote…
- CVE-2017-140952 PoCsA vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote…
- CVE-2017-140962 PoCsA stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow…
- CVE-2017-140972 PoCsAn improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an…
- CVE-2017-141051 PoCHiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore…
- CVE-2017-141081 PoClibgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins…
- CVE-2017-141251 PoCSQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary…
- CVE-2017-141261 PoCThe Participants Database plugin before 1.7.5.10 for WordPress has XSS.
- CVE-2017-141321 PoCJasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20,…
- CVE-2017-141351 PoCenigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to…
- CVE-2017-141381 PoCImageMagick 7.0.6-5 has a memory leak vulnerability in ReadWEBPImage in coders/webp.c because memory is not freed in certain error cases,…
- CVE-2017-141391 PoCImageMagick 7.0.6-2 has a memory leak vulnerability in WriteMSLImage in coders/msl.c.
- CVE-2017-141433 PoCsThe getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote…
- CVE-2017-141472 PoCsAn issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a…
- CVE-2017-141532 PoCsThis vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the…
- CVE-2017-141721 PoCIn coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause huge CPU…
- CVE-2017-141731 PoCIn the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition operation…
- CVE-2017-141742 PoCsIn coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF (End of File) check might cause huge…
- CVE-2017-141751 PoCIn coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of File) check might cause huge CPU…
- CVE-2017-141812 PoCsDeleteBitBuffer in libbitbuf/bitbuffer.c in mp4tools aacplusenc 0.17.5 allows remote attackers to cause a denial of service (invalid…
- CVE-2017-141861 PoCA Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web…
- CVE-2017-141871 PoCA local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below…
- CVE-2017-142191 PoCXSS (persistent) on the Intelbras Wireless N 150Mbps router with firmware WRN 240 allows attackers to steal wireless credentials without…
- CVE-2017-142431 PoCAn authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly…
- CVE-2017-142441 PoCAn authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to…
- CVE-2017-142571 PoCIn the SDK in Bento4 1.5.0-616, AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp contains a Read Memory Access Violation…
- CVE-2017-142581 PoCIn the SDK in Bento4 1.5.0-616, SetItemCount in Core/Ap4StscAtom.h file contains a Write Memory Access Violation vulnerability. It is…
- CVE-2017-142591 PoCIn the SDK in Bento4 1.5.0-616, the AP4_StscAtom class in Ap4StscAtom.cpp contains a Write Memory Access Violation vulnerability. It is…
- CVE-2017-142601 PoCIn the SDK in Bento4 1.5.0-616, the AP4_StssAtom class in Ap4StssAtom.cpp contains a Write Memory Access Violation vulnerability. It is…
- CVE-2017-142611 PoCIn the SDK in Bento4 1.5.0-616, the AP4_StszAtom class in Ap4StszAtom.cpp file contains a Read Memory Access Violation vulnerability. It…
- CVE-2017-142621 PoCOn Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to…
- CVE-2017-142631 PoCHoneywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain…
- CVE-2017-142661 PoCtcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to…
- CVE-2017-142673 PoCsEE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have CSRF, related to goform/AddNewProfile, goform/setWanDisconnect,…
- CVE-2017-142682 PoCsEE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have XSS in the sms_content parameter in a getSMSlist request.
- CVE-2017-142692 PoCsEE 4GEE WiFi MBB (before EE60_00_05.00_31) devices allow remote attackers to obtain sensitive information via a JSONP endpoint, as…
- CVE-2017-143111 PoCThe Winring0x32.sys driver in NetMechanica NetDecision 5.8.2 allows local users to gain privileges via a crafted 0x9C402088 IOCTL call.
- CVE-2017-143222 PoCsThe function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows…
- CVE-2017-143241 PoCIn ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMPCImage in coders/mpc.c, which allows attackers to…
- CVE-2017-143251 PoCIn ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function PersistPixelCache in magick/cache.c, which allows…
- CVE-2017-143261 PoCIn ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to…
- CVE-2017-143351 PoCOn Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to…
- CVE-2017-143391 PoCThe DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force…
- CVE-2017-143411 PoCImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file.
- CVE-2017-143421 PoCImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c via a crafted wpg image file.
- CVE-2017-143431 PoCImageMagick 7.0.6-6 has a memory leak vulnerability in ReadXCFImage in coders/xcf.c via a crafted xcf image file.
- CVE-2017-143441 PoCThis vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the…
- CVE-2017-143551 PoCA potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6. The vulnerability could be…
- CVE-2017-143961 PoCIn osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name,…
- CVE-2017-144001 PoCIn ImageMagick 7.0.7-1 Q16, the PersistPixelCache function in magick/cache.c mishandles the pixel cache nexus, which allows remote…
- CVE-2017-144321 PoCAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially…
- CVE-2017-144331 PoCAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially…
- CVE-2017-144341 PoCAn exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially…
- CVE-2017-144351 PoCAn exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially…
- CVE-2017-144361 PoCAn exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially…
- CVE-2017-144371 PoCAn exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially…
- CVE-2017-144381 PoCExploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially…
- CVE-2017-144391 PoCExploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially…
- CVE-2017-144431 PoCAn exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation…
- CVE-2017-144441 PoCAn exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation…
- CVE-2017-144451 PoCAn exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation…
- CVE-2017-144461 PoCAn exploitable stack-based buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server…
- CVE-2017-144471 PoCAn exploitable buffer overflow vulnerability exists in the PubNub message handler for the 'ad' channel of Insteon Hub running firmware…
- CVE-2017-144511 PoCAn exploitable out-of-bounds read vulnerability exists in libevm (Ethereum Virtual Machine) of CPP-Ethereum. A specially crafted smart…
- CVE-2017-144521 PoCAn exploitable buffer overflow vulnerability exists in the PubNub message handler for the "control" channel of Insteon Hub running…
- CVE-2017-144581 PoCAn exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 8.3.2.25013. A…
- CVE-2017-144591 PoCAn exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial…
- CVE-2017-144601 PoCAn exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum client version 1.7.8.…
- CVE-2017-144621 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144631 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144641 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144651 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144661 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144671 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144681 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144691 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144701 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144711 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144721 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144731 PoCAn exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley…
- CVE-2017-144891 PoCThe iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of…
- CVE-2017-144912 PoCsHeap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code…
- CVE-2017-144921 PoCHeap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code…
- CVE-2017-144934 PoCsStack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code…
- CVE-2017-144941 PoCdnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving…
- CVE-2017-144951 PoCMemory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause…
- CVE-2017-144961 PoCInteger underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is…
- CVE-2017-144981 PoCSilverStripe CMS before 3.6.1 has XSS via an SVG document that is mishandled by (1) the Insert Media option in the content editor or (2)…
- CVE-2017-145061 PoCgeminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its…
- CVE-2017-145072 PoCsMultiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL…
- CVE-2017-145081 PoCAn issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).…
- CVE-2017-145091 PoCAn issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A…
- CVE-2017-145101 PoCAn issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26).…
- CVE-2017-145131 PoCDirectory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the…
- CVE-2017-145171 PoCIn Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.
- CVE-2017-145181 PoCIn Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.
- CVE-2017-145191 PoCIn Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display,…
- CVE-2017-145201 PoCIn Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when…
- CVE-2017-145211 PoCIn WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
- CVE-2017-145231 PoCWonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor…
- CVE-2017-145241 PoCMultiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to…
- CVE-2017-145281 PoCThe TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return…
- CVE-2017-145301 PoCWP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create…
- CVE-2017-145355 PoCstrixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
- CVE-2017-145361 PoCtrixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.
- CVE-2017-145375 PoCstrixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to…
- CVE-2017-145961 PoCIn Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.
- CVE-2017-146001 PoCPragyan CMS v3.0 is vulnerable to an Error-Based SQL injection in cms/admin.lib.php via $_GET['del_black'], resulting in Information…
- CVE-2017-146011 PoCPragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information…
- CVE-2017-146041 PoCGNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in…
- CVE-2017-146151 PoCAn FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the…
- CVE-2017-146181 PoCCross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web…
- CVE-2017-146191 PoCCross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2017-146202 PoCsSmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in…
- CVE-2017-146222 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote…
- CVE-2017-146273 PoCsStack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the…
- CVE-2017-146281 PoCIn sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp.
- CVE-2017-146291 PoCIn sam2p 0.49.3, the in_xpm_reader function in in_xpm.cpp has an integer signedness error, leading to a crash when writing to an…
- CVE-2017-146301 PoCIn sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid write operation.
- CVE-2017-146311 PoCIn sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer overflow.
- CVE-2017-146371 PoCIn sam2p 0.49.3, there is an invalid read of size 2 in the parse_rgb function in in_xpm.cpp. However, this can also cause a write to an…
- CVE-2017-146382 PoCsAP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp in Bento4 version 1.5.0-617 has missing NULL checks, leading to a NULL…
- CVE-2017-146392 PoCsAP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect character data types, which causes a…
- CVE-2017-146402 PoCsA NULL pointer dereference was discovered in AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp in Bento4 version 1.5.0-617.…
- CVE-2017-146412 PoCsA NULL pointer dereference was discovered in the AP4_DataAtom class in MetaData/Ap4MetaData.cpp in Bento4 version 1.5.0-617. The…
- CVE-2017-146422 PoCsA NULL pointer dereference was discovered in the AP4_HdlrAtom class in Bento4 version 1.5.0-617. The vulnerability causes a segmentation…
- CVE-2017-146432 PoCsThe AP4_HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leading to a heap-based…
- CVE-2017-146441 PoCA heap-based buffer overflow was discovered in the AP4_HdlrAtom class in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds…
- CVE-2017-146462 PoCsThe AP4_AvccAtom and AP4_HvccAtom classes in Bento4 version 1.5.0-617 do not properly validate data sizes, leading to a heap-based buffer…
- CVE-2017-146501 PoCA Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's…
- CVE-2017-146512 PoCsWSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath…
- CVE-2017-146521 PoCSQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin before 4.5.8 for MyBB allows an unauthenticated remote…
- CVE-2017-146803 PoCsZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.
- CVE-2017-146831 PoCgeminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.
- CVE-2017-146841 PoCIn ImageMagick 7.0.7-4 Q16, a memory leak vulnerability was found in the function ReadVIPSImage in coders/vips.c, which allows attackers…
- CVE-2017-146851 PoCArtifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file,…
- CVE-2017-146861 PoCArtifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User…
- CVE-2017-146871 PoCArtifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file,…
- CVE-2017-147022 PoCsERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object…
- CVE-2017-147031 PoCSQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO…
- CVE-2017-147041 PoCMultiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone…
- CVE-2017-147052 PoCsDenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted…
- CVE-2017-147062 PoCsDenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to…
- CVE-2017-147122 PoCsIn EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
- CVE-2017-147131 PoCIn EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter.
- CVE-2017-147141 PoCIn EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter.
- CVE-2017-147151 PoCIn EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.
- CVE-2017-147161 PoCIn EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.
- CVE-2017-147172 PoCsIn EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
- CVE-2017-147182 PoCsBefore version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.
- CVE-2017-147191 PoCBefore version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip…
- CVE-2017-147201 PoCBefore version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.
- CVE-2017-147212 PoCsBefore version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.
- CVE-2017-147221 PoCBefore version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.
- CVE-2017-147233 PoCsBefore version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly…
- CVE-2017-147241 PoCBefore version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.
- CVE-2017-147251 PoCBefore version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
- CVE-2017-147261 PoCBefore version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.
- CVE-2017-147311 PoCofx_proc_file in ofx_preproc.cpp in LibOFX 0.9.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and…
- CVE-2017-147351 PoCOWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL.
- CVE-2017-147381 PoCFileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the…
- CVE-2017-147421 PoCBuffer overflow in LabF nfsAxe FTP client 3.7 allows an attacker to execute code remotely.
- CVE-2017-147431 PoCFaleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to…
- CVE-2017-147491 PoCJerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly…
- CVE-2017-147571 PoCOpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as…
- CVE-2017-147581 PoCOpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as…
- CVE-2017-147662 PoCsThe Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit()…
- CVE-2017-147951 PoCThe hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (out-of-bounds read and…
- CVE-2017-147961 PoCThe hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (integer underflow and…
- CVE-2017-147981 PoClocal privilege escalation in SUSE postgresql init script
- CVE-2017-148381 PoCTeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
- CVE-2017-148391 PoCTeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
- CVE-2017-148401 PoCTeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
- CVE-2017-148411 PoCMojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
- CVE-2017-148421 PoCMojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
- CVE-2017-148431 PoCMojoomla School Management System for WordPress allows SQL Injection via the id parameter.
- CVE-2017-148441 PoCMojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
- CVE-2017-148451 PoCMojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
- CVE-2017-148461 PoCMojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
- CVE-2017-148471 PoCMojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
- CVE-2017-148482 PoCsWPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
- CVE-2017-148494 PoCsNode.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the…
- CVE-2017-148571 PoCIn Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a…
- CVE-2017-148581 PoCThere is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of…
- CVE-2017-148591 PoCAn Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes…
- CVE-2017-148601 PoCThere is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will…
- CVE-2017-148611 PoCThere is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will…
- CVE-2017-148621 PoCAn Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a…
- CVE-2017-148631 PoCA NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerability causes a…
- CVE-2017-148641 PoCAn Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a…
- CVE-2017-148661 PoCThere is a heap-based buffer overflow in the Exiv2::s2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of…
- CVE-2017-149041 PoCIn Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a crafted binder request…
- CVE-2017-149371 PoCThe airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to the internal CAN bus…
- CVE-2017-149391 PoCdecode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a…
- CVE-2017-149423 PoCsIntelbras WRN 150 devices allow remote attackers to read the configuration file, and consequently bypass authentication, via a direct…
- CVE-2017-149451 PoCArtifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted…
- CVE-2017-149461 PoCArtifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted…
- CVE-2017-149471 PoCArtifex GSView 6.0 Beta on Windows allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file,…
- CVE-2017-149541 PoCThe waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which…
- CVE-2017-149551 PoCCheck_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote…
- CVE-2017-149562 PoCsAlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the…
- CVE-2017-149602 PoCsxDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection.
- CVE-2017-149611 PoCIn IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from…
- CVE-2017-149771 PoCThe FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of…
- CVE-2017-149791 PoCGxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read arbitrary…
- CVE-2017-1498011 PoCsBuffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to…
- CVE-2017-149811 PoCCross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in…
- CVE-2017-149901 PoCWordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as…
- CVE-2017-149941 PoCReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via…