|
199431
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-1000476
|
2024-11-21 12:04 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199432
|
6.5 |
MEDIUM
Network
|
mautic acquia
|
mautic
|
Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user…
|
CWE-22
Path Traversal
|
CVE-2017-1000490
|
2024-11-21 12:04 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199433
|
8.1 |
HIGH
Network
|
mautic acquia
|
mautic
|
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address
|
CWE-287
Improper Authentication
|
CVE-2017-1000489
|
2024-11-21 12:04 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199434
|
6.1 |
MEDIUM
Network
|
mautic acquia
|
mautic
|
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000488
|
2024-11-21 12:04 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199435
|
9.8 |
CRITICAL
Network
|
awstats debian
|
awstats debian_linux
|
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
|
CWE-22
Path Traversal
|
CVE-2017-1000501
|
2024-11-21 12:04 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199436
|
5.4 |
MEDIUM
Network
|
lavalite
|
lavalite
|
LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000467
|
2024-11-21 12:04 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199437
|
8.8 |
HIGH
Network
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as dele…
|
CWE-352
Origin Validation Error
|
CVE-2017-1000499
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199438
|
7.8 |
HIGH
Local
|
androidsvg_project
|
androidsvg
|
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
|
CWE-611
XXE
|
CVE-2017-1000498
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199439
|
9.8 |
CRITICAL
Network
|
pepperminty-wiki_project
|
pepperminty-wiki
|
Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution
|
CWE-611
XXE
|
CVE-2017-1000497
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199440
|
8.8 |
HIGH
Network
|
commsy
|
commsy
|
Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code.
|
CWE-611
XXE
|
CVE-2017-1000496
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|