|
198731
|
9.8 |
CRITICAL
Network
|
gnu
|
ncurses
|
In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2017-10685
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198732
|
9.8 |
CRITICAL
Network
|
gnu
|
ncurses
|
In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10684
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198733
|
7.8 |
HIGH
Local
|
nasm canonical
|
netwide_assembler ubuntu_linux
|
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function…
|
CWE-416
Use After Free
|
CVE-2017-10686
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198734
|
7.5 |
HIGH
Network
|
mpg123
|
mpg123
|
In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-10683
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198735
|
9.8 |
CRITICAL
Network
|
piwigo
|
piwigo
|
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or stat…
|
CWE-89
SQL Injection
|
CVE-2017-10682
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198736
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request.
|
CWE-352
Origin Validation Error
|
CVE-2017-10681
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198737
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted re…
|
CWE-352
Origin Validation Error
|
CVE-2017-10680
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198738
|
7.5 |
HIGH
Network
|
piwigo
|
piwigo
|
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID…
|
CWE-200
Information Exposure
|
CVE-2017-10679
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198739
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.
|
CWE-352
Origin Validation Error
|
CVE-2017-10678
|
2024-11-21 12:06 |
2017-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198740
|
6.1 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.
|
CWE-79
Cross-site Scripting
|
CVE-2017-10673
|
2024-11-21 12:06 |
2017-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|