|
198551
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
The read_user_chunk_callback function in coders\png.c in ImageMagick 7.0.6-1 Q16 2017-06-21 (beta) has memory leak vulnerabilities via crafted PNG files.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-11310
|
2024-11-21 12:07 |
2017-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198552
|
8.1 |
HIGH
Network
|
heimdal_project freebsd samba apple debian
|
heimdal freebsd samba mac_os_x iphone_os debian_linux
|
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2017-11103
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198553
|
8.8 |
HIGH
Network
|
rack-cors_project debian
|
rack-cors debian_linux
|
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com dom…
|
NVD-CWE-noinfo
|
CVE-2017-11173
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198554
|
6.1 |
MEDIUM
Network
|
finecms_project
|
finecms
|
FineCMS through 2017-07-12 allows XSS in visitors.php because JavaScript in visited URLs is not restricted either during logging or during the reading of logs, a different vulnerability than CVE-2017…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11202
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198555
|
5.4 |
MEDIUM
Network
|
finecms_project
|
finecms
|
application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11201
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198556
|
8.8 |
HIGH
Network
|
finecms_project
|
finecms
|
SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter.
|
CWE-89
SQL Injection
|
CVE-2017-11200
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198557
|
6.1 |
MEDIUM
Network
|
finecms_project
|
finecms
|
Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote attackers to inject arbitrary web script or HTML via the folder, id, or nam…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11198
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198558
|
9.8 |
CRITICAL
Network
|
xoops
|
xoops
|
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of …
|
CWE-89
SQL Injection
|
CVE-2017-11174
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198559
|
8.8 |
HIGH
Network
|
pulsesecure
|
pulse_connect_secure
|
Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malici…
|
CWE-352
Origin Validation Error
|
CVE-2017-11196
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198560
|
6.1 |
MEDIUM
Network
|
pulsesecure
|
pulse_connect_secure
|
Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11195
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|