|
198541
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-600_b1_firmware
|
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the …
|
CWE-22
Path Traversal
|
CVE-2017-12943
|
2024-11-21 12:10 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198542
|
9.8 |
CRITICAL
Network
|
rarlab
|
unrar
|
libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12942
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198543
|
9.8 |
CRITICAL
Network
|
rarlab
|
unrar
|
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12941
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198544
|
9.8 |
CRITICAL
Network
|
rarlab
|
unrar
|
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12940
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198545
|
9.8 |
CRITICAL
Network
|
unity3d
|
unity_editor
|
A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before…
|
CWE-20
Improper Input Validation
|
CVE-2017-12939
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198546
|
7.5 |
HIGH
Network
|
rarlab
|
unrar
|
UnRAR before 5.5.7 allows remote attackers to bypass a directory-traversal protection mechanism via vectors involving a symlink to the . directory, a symlink to the .. directory, and a regular file.
|
CWE-22
Path Traversal
|
CVE-2017-12938
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198547
|
8.8 |
HIGH
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12937
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198548
|
8.8 |
HIGH
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.
|
CWE-416
Use After Free
|
CVE-2017-12936
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198549
|
8.8 |
HIGH
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12935
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198550
|
7.5 |
HIGH
Network
|
php
|
php
|
ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/…
|
CWE-416
Use After Free
|
CVE-2017-12934
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|