|
198511
|
6.1 |
MEDIUM
Network
|
dokuwiki
|
dokuwiki
|
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language name in a code element, in /inc/parser/xhtml.php. An attacker can create or edit a wiki with this element to trigger Ja…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12979
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198512
|
5.4 |
MEDIUM
Network
|
cacti
|
cacti
|
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12978
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198513
|
7.5 |
HIGH
Network
|
ccfile
|
cc_file_transfer
|
In Youngzsoft CCFile (aka CC File Transfer) 3.6, by sending a crafted HTTP request, it is possible for a malicious user to remotely crash the affected software. No authentication is required. An exam…
|
CWE-20
Improper Input Validation
|
CVE-2017-12784
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198514
|
7.2 |
HIGH
Network
|
10web
|
photo_gallery
|
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in a…
|
CWE-89
SQL Injection
|
CVE-2017-12977
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198515
|
8.8 |
HIGH
Network
|
git-annex_project
|
git-annex
|
git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxyCommand= URL, a rel…
|
CWE-20
Improper Input Validation
|
CVE-2017-12976
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198516
|
7.5 |
HIGH
Network
|
connect2id
|
nimbus_jose\+jwt
|
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2017-12974
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198517
|
3.1 |
LOW
Network
|
connect2id
|
nimbus_jose\+jwt
|
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2017-12973
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198518
|
7.5 |
HIGH
Network
|
connect2id
|
nimbus_jose\+jwt
|
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authe…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2017-12972
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198519
|
6.5 |
MEDIUM
Network
|
asn1c_project
|
asn1c
|
The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.28 allows remote attackers to cause a denial of service (segmentation fault) via a crafted .asn1 file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12966
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198520
|
6.5 |
MEDIUM
Network
|
gnu
|
binutils
|
The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (stack-based buffer…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12967
|
2024-11-21 12:10 |
2017-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|