|
198061
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-11751
|
2024-11-21 12:08 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198062
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-11750
|
2024-11-21 12:08 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198063
|
7.5 |
HIGH
Network
|
yaml-cpp_project
|
yaml-cpp
|
The function "Token& Scanner::peek" in scanner.cpp in yaml-cpp 0.5.3 and earlier allows remote attackers to cause a denial of service (assertion failure and application exit) via a '!2' string.
|
CWE-617
Reachable Assertion
|
CVE-2017-11692
|
2024-11-21 12:08 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198064
|
7.8 |
HIGH
Local
|
internet-soft
|
ftp_commander
|
InternetSoft FTP Commander 8.02 and prior has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll file.
|
CWE-426
Untrusted Search Path
|
CVE-2017-11749
|
2024-11-21 12:08 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198065
|
7.8 |
HIGH
Local
|
softonic
|
spider_player
|
VIT Spider Player 2.5.3 has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll, olepro32.dll, dsound.dll, or AUDIOSES.dll file.
|
CWE-426
Untrusted Search Path
|
CVE-2017-11748
|
2024-11-21 12:08 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198066
|
5.5 |
MEDIUM
Local
|
tinyproxy_project
|
tinyproxy
|
main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leverag…
|
CWE-269
Improper Privilege Management
|
CVE-2017-11747
|
2024-11-21 12:08 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198067
|
7.5 |
HIGH
Network
|
inversepath
|
tenshi
|
Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tens…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2017-11746
|
2024-11-21 12:08 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198068
|
6.1 |
MEDIUM
Network
|
modx
|
modx_revolution
|
In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when t…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11744
|
2024-11-21 12:08 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198069
|
7.8 |
HIGH
Local
|
libexpat_project
|
libexpat
|
The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working d…
|
CWE-426
Untrusted Search Path
|
CVE-2017-11742
|
2024-11-21 12:08 |
2017-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198070
|
6.1 |
MEDIUM
Network
|
rspamd_project
|
rspamd
|
interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.
|
CWE-79
Cross-site Scripting
|
CVE-2017-11737
|
2024-11-21 12:08 |
2017-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|