|
198421
|
7.8 |
HIGH
Local
|
rarzilla
|
unrar-free
|
unrarlib.c in unrar-free 0.0.1, when _DEBUG_LOG mode is enabled, might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspeci…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11190
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198422
|
6.5 |
MEDIUM
Network
|
rarzilla
|
unrar-free
|
unrarlib.c in unrar-free 0.0.1 might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash), which could be relevant if unrarlib is used as library code …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-11189
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198423
|
7.5 |
HIGH
Network
|
imagemagick
|
imagemagick
|
The ReadDPXImage function in coders\dpx.c in ImageMagick 7.0.6-0 has a large loop vulnerability that can cause CPU exhaustion via a crafted DPX file, related to lack of an EOF check.
|
CWE-834
Excessive Iteration
|
CVE-2017-11188
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198424
|
9.8 |
CRITICAL
Network
|
phpmyfaq
|
phpmyfaq
|
phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2017-11187
|
2024-11-21 12:07 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198425
|
9.8 |
CRITICAL
Network
|
finecms_project
|
finecms
|
FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence in a domain name, as demonstrated by the ',phpinfo(…
|
CWE-94
Code Injection
|
CVE-2017-11167
|
2024-11-21 12:07 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198426
|
9.8 |
CRITICAL
Network
|
datataker
|
dt80_dex_firmware
|
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.
|
CWE-200
Information Exposure
|
CVE-2017-11165
|
2024-11-21 12:07 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198427
|
5.4 |
MEDIUM
Network
|
fairsketch
|
rise_ultimate_project_manager
|
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the My Profile section. All input fields are vulnerable.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11182
|
2024-11-21 12:07 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198428
|
5.4 |
MEDIUM
Network
|
fairsketch
|
rise_ultimate_project_manager
|
In Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the Messaging section. Subject and Message fields are vulnerable.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11181
|
2024-11-21 12:07 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198429
|
6.1 |
MEDIUM
Network
|
finecms_project
|
finecms
|
FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Agent header of an HTTP request or (2) the username entered on the login scre…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11180
|
2024-11-21 12:07 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198430
|
6.1 |
MEDIUM
Network
|
finecms_project
|
finecms
|
FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when registering a user account.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11179
|
2024-11-21 12:07 |
2017-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|