|
198271
|
7.8 |
HIGH
Local
|
openexif_project
|
openexif
|
The ExifImageFile::readDQT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted j…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11116
|
2024-11-21 12:07 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198272
|
5.5 |
MEDIUM
Local
|
openexif_project
|
openexif
|
The ExifJpegHUFFTable::deriveTable function in ExifHuffmanTable.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a cra…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11115
|
2024-11-21 12:07 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198273
|
5.5 |
MEDIUM
Local
|
twibright
|
links
|
The put_chars function in html_r.c in Twibright Links 2.14 allows remote attackers to cause a denial of service (buffer over-read) via a crafted HTML file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11114
|
2024-11-21 12:07 |
2017-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198274
|
9.8 |
CRITICAL
Network
|
glpi-project
|
glpi
|
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
|
CWE-89
SQL Injection
|
CVE-2017-11184
|
2024-11-21 12:07 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198275
|
4.9 |
MEDIUM
Network
|
glpi-project
|
glpi
|
front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.
|
CWE-20
Improper Input Validation
|
CVE-2017-11183
|
2024-11-21 12:07 |
2017-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198276
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_portal
|
Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary web script or HTML via the responsecode parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2017-11460
|
2024-11-21 12:07 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198277
|
9.8 |
CRITICAL
Network
|
sap
|
trex
|
SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Not…
|
CWE-94
Code Injection
|
CVE-2017-11459
|
2024-11-21 12:07 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198278
|
6.1 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, a…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11458
|
2024-11-21 12:07 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198279
|
6.5 |
MEDIUM
Network
|
sap
|
netweaver_application_server_java
|
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attac…
|
CWE-611
XXE
|
CVE-2017-11457
|
2024-11-21 12:07 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198280
|
5.5 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options …
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11434
|
2024-11-21 12:07 |
2017-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|