|
199601
|
7.5 |
HIGH
Network
|
koji_project
|
koji
|
Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.
|
CWE-20
Improper Input Validation
|
CVE-2017-1002153
|
2024-11-21 12:04 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199602
|
7.5 |
HIGH
Network
|
haxx
|
libcurl
|
libcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in (anonymous or not), it asks the server for the current directory wi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000254
|
2024-11-21 12:04 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199603
|
7.8 |
HIGH
Local
|
redhat centos linux
|
enterprise_linux centos linux_kernel
|
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability w…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000253
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199604
|
8.8 |
HIGH
Network
|
frappe
|
frappe
|
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.
|
CWE-89
SQL Injection
|
CVE-2017-1000120
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199605
|
7.2 |
HIGH
Network
|
octobercms
|
october
|
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-1000119
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199606
|
7.5 |
HIGH
Network
|
akka
|
http_server
|
Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000118
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199607
|
8.8 |
HIGH
Network
|
git-scm
|
git
|
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Suc…
|
CWE-601
Open Redirect
|
CVE-2017-1000117
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199608
|
9.8 |
CRITICAL
Network
|
mercurial debian redhat
|
mercurial debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_serv…
|
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
|
CWE-78
OS Command
|
CVE-2017-1000116
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199609
|
7.5 |
HIGH
Network
|
mercurial debian redhat
|
mercurial debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_serv…
|
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
|
CWE-59
Link Following
|
CVE-2017-1000115
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199610
|
3.1 |
LOW
Network
|
jenkins
|
datadog
|
The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API key is stored encrypted on disk, it was transmitted in plain text as part of the …
|
CWE-200
Information Exposure
|
CVE-2017-1000114
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|