|
197991
|
8.8 |
HIGH
Network
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008
|
The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…
|
CWE-20
Improper Input Validation
|
CVE-2017-11763
|
2024-11-21 12:08 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197992
|
8.8 |
HIGH
Network
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_server_2016 windows_7 windows_10 windows_8.1 windows_server_2008
|
The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…
|
CWE-20
Improper Input Validation
|
CVE-2017-11762
|
2024-11-21 12:08 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197993
|
7.8 |
HIGH
Local
|
pl32
|
photoline
|
A memory corruption vulnerability exists in the .TGA parsing functionality of Computerinsel Photoline 20.02. A specially crafted .TGA file can cause an out of bounds write resulting in potential code…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12106
|
2024-11-21 12:08 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197994
|
9.8 |
CRITICAL
Network
|
redhat
|
jboss_enterprise_application_platform
|
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classe…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-12149
|
2024-11-21 12:08 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197995
|
9.8 |
CRITICAL
Network
|
openvpn debian
|
openvpn debian_linux
|
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-12166
|
2024-11-21 12:08 |
2017-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197996
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omi…
|
NVD-CWE-noinfo
|
CVE-2017-12154
|
2024-11-21 12:08 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197997
|
9.8 |
CRITICAL
Network
|
pureftpd fedoraproject
|
pure-ftpd fedora
|
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with defau…
|
NVD-CWE-noinfo
|
CVE-2017-12170
|
2024-11-21 12:08 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197998
|
4.4 |
MEDIUM
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-12153
|
2024-11-21 12:08 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197999
|
6.0 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) b…
|
-
|
CVE-2017-12168
|
2024-11-21 12:08 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198000
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
|
CWE-200
Information Exposure
|
CVE-2017-12157
|
2024-11-21 12:08 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|