|
198851
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePICTImage in coders/pict.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-12665
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198852
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePALMImage in coders/palm.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-12664
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198853
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteMAPImage in coders/map.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-12663
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198854
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePDFImage in coders/pdf.c.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-12662
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198855
|
6.1 |
MEDIUM
Network
|
nexusphp_project
|
nexusphp
|
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12655
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198856
|
7.5 |
HIGH
Network
|
sap
|
netweaver_application_server_java
|
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot…
|
CWE-22
Path Traversal
|
CVE-2017-12637
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198857
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
The ReadPICTImage function in coders/pict.c in ImageMagick 7.0.6-3 allows attackers to cause a denial of service (memory leak) via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-12654
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198858
|
7.8 |
HIGH
Local
|
360totalsecurity
|
360_total_security
|
360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2017-12653
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198859
|
8.8 |
HIGH
Network
|
loginizer
|
loginizer
|
Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.
|
CWE-352
Origin Validation Error
|
CVE-2017-12651
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198860
|
9.8 |
CRITICAL
Network
|
loginizer
|
loginizer
|
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.
|
CWE-89
SQL Injection
|
CVE-2017-12650
|
2024-11-21 12:09 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|