|
199501
|
6.1 |
MEDIUM
Network
|
phoenixframework
|
phoenix
|
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering …
|
CWE-601
Open Redirect
|
CVE-2017-1000163
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199502
|
9.8 |
CRITICAL
Network
|
xrootd
|
xrootd
|
ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution
|
CWE-78
OS Command
|
CVE-2017-1000215
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199503
|
7.5 |
HIGH
Network
|
jqueryfiletree_project
|
jqueryfiletree
|
jqueryFileTree 2.1.5 and older Directory Traversal
|
CWE-22
Path Traversal
|
CVE-2017-1000170
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199504
|
9.8 |
CRITICAL
Network
|
quickerbb_project
|
quickerbb
|
QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead to the complete takeover of the server hosting QuickerBB.
|
CWE-20
Improper Input Validation
|
CVE-2017-1000169
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199505
|
6.5 |
MEDIUM
Network
|
sodiumoxide_project
|
sodiumoxide
|
sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys
|
NVD-CWE-noinfo
|
CVE-2017-1000168
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199506
|
9.8 |
CRITICAL
Network
|
cygnux
|
syspass
|
Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login…
|
NVD-CWE-noinfo
|
CVE-2017-1000192
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199507
|
7.5 |
HIGH
Network
|
jool
|
jool
|
Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-1000191
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199508
|
9.8 |
CRITICAL
Network
|
alchemist-elixir
|
alchemist-server
|
Elixir's vim plugin, alchemist.vim is vulnerable to remote code execution in the bundled alchemist-server. A malicious website can execute requests against an ephemeral port on localhost that are the…
|
NVD-CWE-noinfo
|
CVE-2017-1000212
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199509
|
5.3 |
MEDIUM
Network
|
lynx_project
|
lynx
|
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
|
CWE-416
Use After Free
|
CVE-2017-1000211
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199510
|
9.8 |
CRITICAL
Network
|
htslib
|
htslib
|
samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000206
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|