|
199461
|
8.8 |
HIGH
Network
|
gnome debian canonical
|
gdk-pixbuf debian_linux ubuntu_linux
|
Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-1000422
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199462
|
9.8 |
CRITICAL
Network
|
lcdf debian
|
gifsicle debian_linux
|
Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution
|
CWE-416
Use After Free
|
CVE-2017-1000421
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199463
|
7.5 |
HIGH
Network
|
syncthing
|
syncthing
|
Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
|
CWE-59
Link Following
|
CVE-2017-1000420
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199464
|
7.5 |
HIGH
Network
|
phpbb
|
phpbb
|
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal se…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-1000419
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199465
|
9.8 |
CRITICAL
Network
|
bro
|
bro
|
Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-1000458
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199466
|
4.8 |
MEDIUM
Network
|
mojoportal
|
mojoportal
|
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires aut…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000457
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199467
|
8.8 |
HIGH
Network
|
freedesktop debian
|
poppler debian_linux
|
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000456
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199468
|
7.8 |
HIGH
Local
|
mindwerks
|
wildmidi
|
The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000418
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199469
|
5.5 |
MEDIUM
Local
|
gnu
|
guixsd
|
GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assu…
|
CWE-346
Origin Validation Error
|
CVE-2017-1000455
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199470
|
7.8 |
HIGH
Local
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1
|
CWE-74
Injection
|
CVE-2017-1000454
|
2024-11-21 12:04 |
2018-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|