|
198481
|
8.8 |
HIGH
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12935
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198482
|
7.5 |
HIGH
Network
|
php
|
php
|
ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/…
|
CWE-416
Use After Free
|
CVE-2017-12934
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198483
|
9.8 |
CRITICAL
Network
|
php
|
php
|
The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a buffer over-read while unserializing untrusted data…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-12933
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198484
|
9.8 |
CRITICAL
Network
|
php
|
php
|
ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted data, related to improper use of the hash API for …
|
CWE-416
Use After Free
|
CVE-2017-12932
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198485
|
6.1 |
MEDIUM
Network
|
cacti
|
cacti
|
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12927
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198486
|
9.8 |
CRITICAL
Network
|
nexusphp_project
|
nexusphp
|
SQL injection vulnerability in massmail.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the or parameter.
|
CWE-89
SQL Injection
|
CVE-2017-12910
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198487
|
9.8 |
CRITICAL
Network
|
nexusphp_project
|
nexusphp
|
SQL injection vulnerability in modtask.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.
|
CWE-89
SQL Injection
|
CVE-2017-12909
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198488
|
9.8 |
CRITICAL
Network
|
nexusphp_project
|
nexusphp
|
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the conusr parameter.
|
CWE-89
SQL Injection
|
CVE-2017-12908
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198489
|
6.1 |
MEDIUM
Network
|
nexusphp_project
|
nexusphp
|
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12907
|
2024-11-21 12:10 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198490
|
7.8 |
HIGH
Local
|
foxitsoftware
|
pdf_compressor
|
Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the curren…
|
CWE-426
Untrusted Search Path
|
CVE-2017-12892
|
2024-11-21 12:10 |
2017-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|