|
197681
|
7.8 |
HIGH
Local
|
aerohive
|
hivemanager_classic
|
HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive. An au…
|
CWE-20
Improper Input Validation
|
CVE-2017-14105
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197682
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering…
|
CWE-369
Divide By Zero
|
CVE-2017-14106
|
2024-11-21 12:12 |
2017-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197683
|
8.8 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote attackers to conduct …
|
CWE-416
Use After Free
|
CVE-2017-14103
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197684
|
7.8 |
HIGH
Local
|
mimedefang
|
mimedefang
|
MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account…
|
CWE-665
Improper Initialization
|
CVE-2017-14102
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197685
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.
|
CWE-89
SQL Injection
|
CVE-2017-14076
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197686
|
6.1 |
MEDIUM
Network
|
nexusphp
|
nexusphp
|
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14070
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197687
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.
|
CWE-89
SQL Injection
|
CVE-2017-14069
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197688
|
9.8 |
CRITICAL
Network
|
ruby-lang debian canonical redhat
|
ruby debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise…
|
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14064
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197689
|
7.5 |
HIGH
Network
|
asynchttpclient_project
|
async-http-client
|
Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. S…
|
CWE-20
Improper Input Validation
|
CVE-2017-14063
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197690
|
9.8 |
CRITICAL
Network
|
gnu debian
|
libidn2 debian_linux
|
Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-14062
|
2024-11-21 12:12 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|