|
197601
|
9.8 |
CRITICAL
Network
|
blog_project
|
blog
|
SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php.
|
CWE-89
SQL Injection
|
CVE-2017-14345
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197602
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.6-6 has a memory leak vulnerability in ReadXCFImage in coders/xcf.c via a crafted xcf image file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-14343
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197603
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c via a crafted wpg image file.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-14342
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197604
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-14341
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197605
|
8.1 |
HIGH
Network
|
misp-project
|
misp
|
When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate…
|
CWE-287
Improper Authentication
|
CVE-2017-14337
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197606
|
7.8 |
HIGH
Local
|
jungo
|
windriver
|
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system i…
|
CWE-20
Improper Input Validation
|
CVE-2017-14344
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197607
|
8.8 |
HIGH
Local
|
xen
|
xen
|
A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accou…
|
NVD-CWE-noinfo
|
CVE-2017-14319
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197608
|
6.5 |
MEDIUM
Local
|
xen
|
xen
|
An issue was discovered in Xen 4.5.x through 4.9.x. The function `__gnttab_cache_flush` handles GNTTABOP_cache_flush grant table operations. It checks to see if the calling domain is the owner of the…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14318
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197609
|
5.6 |
MEDIUM
Local
|
xen
|
xen
|
A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a race in cxenstored may cause a double-free. The xens…
|
CWE-362
Race Condition
|
CVE-2017-14317
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197610
|
8.8 |
HIGH
Local
|
xen
|
xen
|
A parameter verification issue was discovered in Xen through 4.9.x. The function `alloc_heap_pages` allows callers to specify the first NUMA node that should be used for allocations through the `memf…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-14316
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|