CVE-2017-5000 to CVE-2017-5999
157 CVEs with public proof-of-concept exploits.
- CVE-2017-50051 PoCStack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus…
- CVE-2017-50071 PoCBlink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, incorrectly handled the sequence of…
- CVE-2017-50701 PoCKEVType confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote…
- CVE-2017-51211 PoCInappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker…
- CVE-2017-512312 PoCsInsufficient data validation in waitid allowed an user to escape sandboxes on Linux.
- CVE-2017-51242 PoCsIncorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts…
- CVE-2017-51351 PoCCertain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor…
- CVE-2017-51461 PoCAn issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Sensitive…
- CVE-2017-51621 PoCAn issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives…
- CVE-2017-51731 PoCAn Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version…
- CVE-2017-51741 PoCAn Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass…
- CVE-2017-51771 PoCA Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior. A stack-based buffer overflow vulnerability…
- CVE-2017-51801 PoCFirejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent…
- CVE-2017-52061 PoCFirejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox…
- CVE-2017-52071 PoCFirejail before 0.9.44.4, when running a bandwidth command, allows local users to gain root privileges via the --shell argument.
- CVE-2017-52141 PoCThe Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of…
- CVE-2017-52151 PoCThe Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a "safe file…
- CVE-2017-52233 PoCsAn issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it…
- CVE-2017-52252 PoCsLibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted…
- CVE-2017-52261 PoCWhen executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to…
- CVE-2017-52271 PoCQNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by reading data in…
- CVE-2017-52541 PoCIn version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of…
- CVE-2017-52552 PoCsIn version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management…
- CVE-2017-52591 PoCIn versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available…
- CVE-2017-52601 PoCIn versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available…
- CVE-2017-52611 PoCIn versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative…
- CVE-2017-52621 PoCIn versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive…
- CVE-2017-52641 PoCVersions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions…
- CVE-2017-53291 PoCPalo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds…
- CVE-2017-53401 PoCZend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows…
- CVE-2017-53442 PoCsAn issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path…
- CVE-2017-53461 PoCSQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to…
- CVE-2017-53583 PoCsStack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the…
- CVE-2017-53594 PoCsEasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.
- CVE-2017-53672 PoCsMultiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder v1.30 and v1.29, an open-source CCTV…
- CVE-2017-53682 PoCsZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a…
- CVE-2017-53753 PoCsJIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability…
- CVE-2017-53781 PoCHashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered…
- CVE-2017-53861 PoCWebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential…
- CVE-2017-53871 PoCThe existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on…
- CVE-2017-53941 PoCA location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of…
- CVE-2017-53951 PoCMalicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is…
- CVE-2017-54042 PoCsA use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside…
- CVE-2017-54071 PoCUsing SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a…
- CVE-2017-54091 PoCThe Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the…
- CVE-2017-54111 PoCA use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage…
- CVE-2017-54153 PoCsAn attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user…
- CVE-2017-54201 PoCA "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an…
- CVE-2017-54211 PoCA malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what…
- CVE-2017-54281 PoCAn integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the…
- CVE-2017-54331 PoCA use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the…
- CVE-2017-54381 PoCA use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This…
- CVE-2017-54391 PoCA use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially…
- CVE-2017-54401 PoCA use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating…
- CVE-2017-54472 PoCsAn out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could…
- CVE-2017-54501 PoCA mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed…
- CVE-2017-54511 PoCA mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by…
- CVE-2017-54551 PoCThe internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with…
- CVE-2017-54561 PoCA mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This…
- CVE-2017-54652 PoCsAn out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible…
- CVE-2017-54731 PoCCross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary…
- CVE-2017-548716 PoCswp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not…
- CVE-2017-54881 PoCMultiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote attackers to inject…
- CVE-2017-54891 PoCCross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authentication of…
- CVE-2017-54901 PoCCross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in WordPress before…
- CVE-2017-54911 PoCwp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with…
- CVE-2017-54921 PoCCross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7.1 allows remote…
- CVE-2017-54931 PoCwp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys,…
- CVE-2017-54961 PoCSawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.
- CVE-2017-54981 PoClibjasper/include/jasper/jas_math.h in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving…
- CVE-2017-54991 PoCInteger overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted…
- CVE-2017-55001 PoClibjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift…
- CVE-2017-55011 PoCInteger overflow in libjasper/jpc/jpc_tsfb.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted…
- CVE-2017-55021 PoClibjasper/jp2/jp2_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift…
- CVE-2017-55031 PoCThe dec_clnpass function in libjasper/jpc/jpc_t1dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid…
- CVE-2017-55041 PoCThe jpc_undo_roi function in libjasper/jpc/jpc_dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid…
- CVE-2017-55051 PoCThe jas_matrix_asl function in jas_seq.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and…
- CVE-2017-55161 PoCMultiple cross-site scripting (XSS) vulnerabilities in the user forms in GeniXCMS through 0.0.8 allow remote attackers to inject arbitrary…
- CVE-2017-55171 PoCSQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2017-55181 PoCThe media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a…
- CVE-2017-55191 PoCSQL injection vulnerability in Posts.class.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2017-55201 PoCThe media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP…
- CVE-2017-55215 PoCsKEVAn issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and…
- CVE-2017-55851 PoCOpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and…
- CVE-2017-55862 PoCsOpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized…
- CVE-2017-55942 PoCsAn issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's…
- CVE-2017-56073 PoCsSplunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before…
- CVE-2017-56101 PoCwp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a…
- CVE-2017-56111 PoCSQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute…
- CVE-2017-56121 PoCCross-site scripting (XSS) vulnerability in wp-admin/includes/class-wp-posts-list-table.php in the posts list table in WordPress before…
- CVE-2017-56181 PoCGNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking…
- CVE-2017-56301 PoCPECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a…
- CVE-2017-56312 PoCsAn issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is…
- CVE-2017-56333 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers…
- CVE-2017-56371 PoCTwo four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused,…
- CVE-2017-5638118 PoCsKEVThe Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and…
- CVE-2017-56453 PoCsIn Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another…
- CVE-2017-56651 PoCThe splt_cue_export_to_file function in cue.c in libmp3splt 0.9.2 allows remote attackers to cause a denial of service (NULL pointer…
- CVE-2017-56661 PoCThe free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and…
- CVE-2017-56713 PoCsHoneywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309…
- CVE-2017-56721 PoCKony Enterprise Mobile Management (EMM) before 4.2.5.2 has the vulnerability of disclosing the private key in clear-text when changing the…
- CVE-2017-56731 PoCIn the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS.…
- CVE-2017-56741 PoCA vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an…
- CVE-2017-56897 PoCsKEVAn unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology…
- CVE-2017-56931 PoCFirmware in the Intel Puma 5, 6, and 7 Series might experience resource depletion or timeout, which allows a network attacker to create a…
- CVE-2017-57052 PoCsMultiple buffer overflows in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local…
- CVE-2017-571519 PoCsSystems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of…
- CVE-2017-57171 PoCType Confusion in Content Protection HECI Service in Intel Graphics Driver allows unprivileged user to elevate privileges via local access.
- CVE-2017-57211 PoCInsufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below…
- CVE-2017-575322 PoCsSystems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an…
- CVE-2017-575410 PoCsSystems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of…
- CVE-2017-57922 PoCsA Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
- CVE-2017-57981 PoCA Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to…
- CVE-2017-57991 PoCA Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to…
- CVE-2017-58151 PoCA Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
- CVE-2017-58163 PoCsA Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
- CVE-2017-58173 PoCsA Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
- CVE-2017-58492 PoCstiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial…
- CVE-2017-58503 PoCshttpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using…
- CVE-2017-58511 PoCThe free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (NULL pointer…
- CVE-2017-58681 PoCCRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers…
- CVE-2017-58692 PoCsDirectory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to…
- CVE-2017-58701 PoCMultiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2017-58713 PoCsOdoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
- CVE-2017-58751 PoCXSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.
- CVE-2017-58761 PoCXSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.
- CVE-2017-58771 PoCXSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.
- CVE-2017-58811 PoCGOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact…
- CVE-2017-58841 PoCgtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary…
- CVE-2017-58851 PoCMultiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow…
- CVE-2017-58992 PoCsDirectory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to…
- CVE-2017-59251 PoCPage table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel…
- CVE-2017-59261 PoCPage table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD…
- CVE-2017-59271 PoCPage table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM…
- CVE-2017-59291 PoCQOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
- CVE-2017-59301 PoCThe AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the…
- CVE-2017-594112 PoCsAn issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be…
- CVE-2017-59421 PoCAn issue was discovered in the WP Mail plugin before 1.2 for WordPress. The replyto parameter when composing a mail allows for a reflected…
- CVE-2017-59451 PoCAn issue was discovered in the PoodLL Filter plugin through 3.0.20 for Moodle. The vulnerability exists due to insufficient filtration of…
- CVE-2017-59481 PoCAn issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due…
- CVE-2017-59511 PoCThe mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial…
- CVE-2017-59541 PoCAn issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be…
- CVE-2017-59611 PoCAn issue was discovered in ionize through 1.0.8. The vulnerability exists due to insufficient filtration of user-supplied data in the…
- CVE-2017-59711 PoCSQL injection vulnerability in NewsBee CMS allow remote attackers to execute arbitrary SQL commands.
- CVE-2017-59722 PoCsThe TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network…
- CVE-2017-59741 PoCHeap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57,…
- CVE-2017-59751 PoCHeap-based buffer overflow in the __zzip_get64 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57,…
- CVE-2017-59761 PoCHeap-based buffer overflow in the zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58,…
- CVE-2017-59771 PoCThe zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (invalid…
- CVE-2017-59781 PoCThe zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (out-of-bounds read…
- CVE-2017-59791 PoCThe prescan_entry function in fseeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference…
- CVE-2017-59801 PoCThe zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer…
- CVE-2017-59811 PoCseeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (assertion failure and crash) via a crafted ZIP file.
- CVE-2017-59824 PoCsDirectory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e…
- CVE-2017-59831 PoCThe JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows…
- CVE-2017-59841 PoCIn libavcodec in Libav 9.21, ff_h264_execute_ref_pic_marking() has a heap-based buffer over-read.
- CVE-2017-59912 PoCsAn issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c…