|
198281
|
7.5 |
HIGH
Network
|
nodejs
|
node.js
|
Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was co…
|
CWE-20
Improper Input Validation
|
CVE-2017-11499
|
2024-11-21 12:07 |
2017-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198282
|
6.5 |
MEDIUM
Network
|
tilde_cms_project
|
tilde_cms
|
An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP resources such as admin/content.php and admin/cont…
|
CWE-200
Information Exposure
|
CVE-2017-11327
|
2024-11-21 12:07 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198283
|
7.5 |
HIGH
Network
|
tilde_cms_project
|
tilde_cms
|
An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipulation.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-11326
|
2024-11-21 12:07 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198284
|
7.5 |
HIGH
Network
|
tilde_cms_project
|
tilde_cms
|
An issue was discovered in Tilde CMS 1.0.1. Arbitrary files can be read via a file=../ attack on actionphp/download.File.php.
|
CWE-200
Information Exposure
|
CVE-2017-11325
|
2024-11-21 12:07 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198285
|
9.8 |
CRITICAL
Network
|
tilde_cms_project
|
tilde_cms
|
An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be trigge…
|
CWE-89
SQL Injection
|
CVE-2017-11324
|
2024-11-21 12:07 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198286
|
8.8 |
HIGH
Network
|
statamic
|
statamic
|
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, creat…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-11422
|
2024-11-21 12:07 |
2017-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198287
|
9.8 |
CRITICAL
Network
|
tcpdump
|
tcpdump
|
tcpdump 4.9.0 has a buffer overflow in the sliplink_print function in print-sl.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11543
|
2024-11-21 12:07 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198288
|
9.8 |
CRITICAL
Network
|
tcpdump
|
tcpdump
|
tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11542
|
2024-11-21 12:07 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198289
|
9.8 |
CRITICAL
Network
|
tcpdump
|
tcpdump
|
tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11541
|
2024-11-21 12:07 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198290
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the GetPixelIndex() function, called from the WritePICONImage function in coders/xpm.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11540
|
2024-11-21 12:07 |
2017-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|