|
198171
|
7.8 |
HIGH
Local
|
fontforge
|
fontforge
|
FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafted otf file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11568
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198172
|
7.5 |
HIGH
Network
|
debian
|
tor
|
debian/tor.init in the Debian tor_0.2.9.11-1~deb9u1 package for Tor was designed to execute aa-exec from the standard system pathname if the apparmor package is installed, but implements this incorre…
|
NVD-CWE-noinfo
|
CVE-2017-11565
|
2024-11-21 12:08 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198173
|
7.5 |
HIGH
Network
|
libsass
|
libsass
|
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
|
CWE-674
Uncontrolled Recursion
|
CVE-2017-11556
|
2024-11-21 12:08 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198174
|
7.5 |
HIGH
Network
|
libsass
|
libsass
|
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2017-11555
|
2024-11-21 12:08 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198175
|
7.5 |
HIGH
Network
|
libsass
|
libsass
|
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
|
CWE-674
Uncontrolled Recursion
|
CVE-2017-11554
|
2024-11-21 12:08 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198176
|
7.5 |
HIGH
Network
|
exiv2
|
exiv2
|
There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26. A crafted input will lead to remote denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2017-11553
|
2024-11-21 12:08 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198177
|
7.8 |
HIGH
Local
|
cyberark
|
viewfinity
|
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option.
|
NVD-CWE-noinfo
|
CVE-2017-11197
|
2024-11-21 12:07 |
2023-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198178
|
9.8 |
CRITICAL
Network
|
sensiolabs
|
symfony
|
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The compo…
|
CWE-284
Improper Access Control
|
CVE-2017-11365
|
2024-11-21 12:07 |
2019-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198179
|
9.8 |
CRITICAL
Network
|
omniauth
|
omniauth_saml
|
OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data wit…
|
CWE-287
Improper Authentication
|
CVE-2017-11430
|
2024-11-21 12:07 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198180
|
9.8 |
CRITICAL
Network
|
clever
|
saml2-js
|
Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without inval…
|
CWE-287
Improper Authentication
|
CVE-2017-11429
|
2024-11-21 12:07 |
2019-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|