|
198351
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
The ReadSCREENSHOTImage function in coders/screenshot.c in ImageMagick before 7.0.6-1 has memory leaks, causing denial of service.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-11447
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198352
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite loop vulnerability that can cause CPU exhaustion via a crafted PES file.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-11446
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198353
|
9.8 |
CRITICAL
Network
|
intelliants
|
subrion_cms
|
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
|
CWE-89
SQL Injection
|
CVE-2017-11445
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198354
|
9.8 |
CRITICAL
Network
|
intelliants
|
subrion_cms
|
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
|
CWE-89
SQL Injection
|
CVE-2017-11444
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198355
|
5.4 |
MEDIUM
Network
|
cpanel
|
whm
|
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11441
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198356
|
4.9 |
MEDIUM
Network
|
sitecore
|
cms
|
In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin/LinqScratchPad.aspx Reference parameter.
|
CWE-22
Path Traversal
|
CVE-2017-11440
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198357
|
5.4 |
MEDIUM
Network
|
sitecore
|
cms
|
In Sitecore 8.2, there is reflected XSS in the shell/Applications/Tools/Run Program parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11439
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198358
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-615
|
D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attackers to obtain access via a TELNET connection.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-11436
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198359
|
9.8 |
CRITICAL
Network
|
humaxdigital
|
hg100r_firmware
|
The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted requests to the management console. The bug is exploitable remotely when the route…
|
CWE-200
Information Exposure
|
CVE-2017-11435
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198360
|
7.5 |
HIGH
Network
|
wireshark
|
wireshark
|
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validati…
|
CWE-20
Improper Input Validation
|
CVE-2017-11411
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|