CVE-2017-7000 to CVE-2017-7999
164 CVEs with public proof-of-concept exploits.
- CVE-2017-70041 PoCAn issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the…
- CVE-2017-70057 PoCsAn issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is…
- CVE-2017-70181 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70371 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70381 PoCA DOMParser XSS issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS…
- CVE-2017-70391 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70401 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70411 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70421 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70431 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70461 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70473 PoCsAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is…
- CVE-2017-70481 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70491 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70561 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70612 PoCsAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70641 PoCAn issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on…
- CVE-2017-70893 PoCsAn issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows…
- CVE-2017-70921 PoCAn issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows…
- CVE-2017-71151 PoCAn issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi"…
- CVE-2017-71172 PoCsAn issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows…
- CVE-2017-71492 PoCsAn issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "StorageKit"…
- CVE-2017-71541 PoCAn issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is…
- CVE-2017-71751 PoCNfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the…
- CVE-2017-71782 PoCsCSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that…
- CVE-2017-71801 PoCNet Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block…
- CVE-2017-71832 PoCsThe TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2)…
- CVE-2017-71843 PoCsThe xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after…
- CVE-2017-71851 PoCUse-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server…
- CVE-2017-71881 PoCZurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl…
- CVE-2017-71991 PoCNessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the…
- CVE-2017-72021 PoCMultiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16. The vulnerabilities exist due to insufficient…
- CVE-2017-72031 PoCA Cross-Site Scripting (XSS) was discovered in ZoneMinder before 1.30.2. The vulnerability exists due to insufficient filtration of…
- CVE-2017-72041 PoCA Cross-Site Scripting (XSS) was discovered in imdbphp 5.1.1. The vulnerability exists due to insufficient filtration of user-supplied…
- CVE-2017-72051 PoCA Cross-Site Scripting (XSS) was discovered in GamePanelX-V3 3.0.12. The vulnerability exists due to insufficient filtration of…
- CVE-2017-72201 PoCOpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized…
- CVE-2017-72212 PoCsOpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users…
- CVE-2017-72281 PoCAn issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix…
- CVE-2017-72302 PoCsA buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrary code via a GET…
- CVE-2017-72311 PoCpngdefry through 2017-03-22 is prone to a heap-based buffer-overflow vulnerability because it fails to properly process a specially…
- CVE-2017-72372 PoCsThe Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks…
- CVE-2017-72402 PoCsAn issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to…
- CVE-2017-72531 PoCDahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via…
- CVE-2017-726934 PoCsKEVBuffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows…
- CVE-2017-72801 PoCAn issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered…
- CVE-2017-72811 PoCAn issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and…
- CVE-2017-72841 PoCAn attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to…
- CVE-2017-72851 PoCA vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to…
- CVE-2017-72901 PoCSQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute…
- CVE-2017-72931 PoCThe Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary…
- CVE-2017-73089 PoCsThe packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size…
- CVE-2017-73106 PoCsA buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before…
- CVE-2017-73121 PoCAn issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account…
- CVE-2017-73141 PoCAn issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a…
- CVE-2017-73171 PoCAn issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka…
- CVE-2017-73582 PoCsIn LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path…
- CVE-2017-73741 PoCUse-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer…
- CVE-2017-73761 PoCBuffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when…
- CVE-2017-73881 PoCA Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtration of…
- CVE-2017-73891 PoCMultiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient…
- CVE-2017-73911 PoCA Cross-Site Scripting (XSS) was discovered in 'Magmi 0.7.22'. The vulnerability exists due to insufficient filtration of user-supplied…
- CVE-2017-73971 PoCBackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian…
- CVE-2017-73981 PoCD-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an…
- CVE-2017-74022 PoCsPixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an…
- CVE-2017-74101 PoCMultiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote…
- CVE-2017-74113 PoCsAn issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is…
- CVE-2017-74151 PoCAtlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST…
- CVE-2017-74411 PoCIn Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a crafted IOCTL with…
- CVE-2017-74423 PoCsNitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.
- CVE-2017-74462 PoCsHelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
- CVE-2017-74472 PoCsHelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
- CVE-2017-74553 PoCsMoxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.
- CVE-2017-74563 PoCsMoxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login…
- CVE-2017-74572 PoCsXML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.
- CVE-2017-74611 PoCDirectory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows…
- CVE-2017-74621 PoCIntellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web…
- CVE-2017-74671 PoCA buffer overflow flaw was found in the way minicom before version 2.7.1 handled VT100 escape sequences. A malicious terminal device could…
- CVE-2017-74722 PoCsThe KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of…
- CVE-2017-74781 PoCOpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that…
- CVE-2017-749430 PoCsKEVSamba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious…
- CVE-2017-750411 PoCsHTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss…
- CVE-2017-75151 PoCpoppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.
- CVE-2017-752516 PoCsA deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an…
- CVE-2017-752925 PoCsNginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module…
- CVE-2017-75332 PoCsRace condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges or cause a denial…
- CVE-2017-75441 PoClibexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c…
- CVE-2017-75511 PoC389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different…
- CVE-2017-75581 PoCA kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info()…
- CVE-2017-75651 PoCSplunk Hadoop Connect App has a path traversal vulnerability that allows remote authenticated users to execute arbitrary code, aka ERP-2041.
- CVE-2017-75713 PoCspublic/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
- CVE-2017-75812 PoCsSQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute…
- CVE-2017-75881 PoCOn certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login…
- CVE-2017-75961 PoCLibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote…
- CVE-2017-75971 PoCtif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might…
- CVE-2017-75981 PoCtif_dirread.c in LibTIFF 4.0.7 might allow remote attackers to cause a denial of service (divide-by-zero error and application crash) via…
- CVE-2017-75991 PoCLibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote…
- CVE-2017-76001 PoCLibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote…
- CVE-2017-76011 PoCLibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause…
- CVE-2017-76021 PoCLibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or…
- CVE-2017-76031 PoCau_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers to cause a denial…
- CVE-2017-76041 PoCau_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a left-shift undefined behavior issue, which might allow remote attackers to…
- CVE-2017-76051 PoCaacplusenc.c in HE-AAC+ Codec (aka libaacplus) 2.0.2 has an assertion failure, which might allow remote attackers to cause a denial of…
- CVE-2017-76061 PoCcoders/rle.c in ImageMagick 7.0.5-4 has an "outside the range of representable values of type unsigned char" undefined behavior issue,…
- CVE-2017-76071 PoCThe handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer…
- CVE-2017-76081 PoCThe ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service…
- CVE-2017-76091 PoCelf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service…
- CVE-2017-76101 PoCThe check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read…
- CVE-2017-76111 PoCThe check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer…
- CVE-2017-76121 PoCThe check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer…
- CVE-2017-76131 PoCelflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a…
- CVE-2017-76156 PoCsMantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.
- CVE-2017-76202 PoCsMantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has…
- CVE-2017-76211 PoCCross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code,…
- CVE-2017-76221 PoCdde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything…
- CVE-2017-76251 PoCIn Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and…
- CVE-2017-76422 PoCsThe sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root…
- CVE-2017-76431 PoCProxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid program.
- CVE-2017-76481 PoCFoscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers…
- CVE-2017-76501 PoCIn Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows…
- CVE-2017-76513 PoCsIn Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with…
- CVE-2017-76792 PoCsIn Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious…
- CVE-2017-76901 PoCProxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary with a Trojan horse…
- CVE-2017-76922 PoCsSquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file…
- CVE-2017-77191 PoCSQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by…
- CVE-2017-77201 PoCBuffer overflow in PrivateTunnel 2.7 and 2.8 allows local attackers to cause a denial of service (SEH overwrite) or possibly have…
- CVE-2017-77221 PoCIn SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc"…
- CVE-2017-77253 PoCsconcrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on…
- CVE-2017-77411 PoCIn libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation…
- CVE-2017-77421 PoCIn libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation…
- CVE-2017-77531 PoCAn out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This…
- CVE-2017-77581 PoCAn out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in…
- CVE-2017-77591 PoCAndroid intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the…
- CVE-2017-77601 PoCThe Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the…
- CVE-2017-77811 PoCAn error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can yield a result…
- CVE-2017-77832 PoCsIf a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the…
- CVE-2017-77881 PoCWhen an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing…
- CVE-2017-78001 PoCA use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation…
- CVE-2017-78171 PoCA spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be…
- CVE-2017-78211 PoCA vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered…
- CVE-2017-78511 PoCD-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to…
- CVE-2017-78522 PoCsD-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the…
- CVE-2017-78551 PoCIn the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.
- CVE-2017-78771 PoCCSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.
- CVE-2017-78811 PoCBigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing…
- CVE-2017-78961 PoCTrend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.
- CVE-2017-78971 PoCA cross-site scripting (XSS) vulnerability in the MantisBT (2.3.x before 2.3.2) Timeline include page, used in My View (my_view_page.php)…
- CVE-2017-79121 PoCHanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and response could…
- CVE-2017-792124 PoCsKEVAn Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530,…
- CVE-2017-79241 PoCAn Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA,…
- CVE-2017-79252 PoCsA Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX,…
- CVE-2017-79382 PoCsStack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of…
- CVE-2017-79481 PoCInteger overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service…
- CVE-2017-79501 PoCNitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.
- CVE-2017-79521 PoCINFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.
- CVE-2017-79532 PoCsINFOR EAM V11.0 Build 201410 has XSS via comment fields.
- CVE-2017-79601 PoCThe cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service…
- CVE-2017-79611 PoCThe cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type…
- CVE-2017-79621 PoCThe iwgif_read_image function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of…
- CVE-2017-79811 PoCTuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component…
- CVE-2017-79901 PoCThe Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to…
- CVE-2017-79913 PoCsExponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of…
- CVE-2017-79942 PoCsThe function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL…
- CVE-2017-79972 PoCsMultiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2017-79981 PoCMultiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary web script or HTML…