CVE-2017-1000427
Last Modified: 21 Nov 2024marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
CVE-2017-1000432
Last Modified: 21 Nov 2024Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
CVE-2017-1000437
Last Modified: 21 Nov 2024Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote code execution.
CVE-2017-1000438
Last Modified: 21 Nov 2024In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, then manipulate the user's data.
CVE-2017-1000426
Last Modified: 21 Nov 2024MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.
CVE-2017-1000431
Last Modified: 21 Nov 2024eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.
CVE-2017-1000430
Last Modified: 21 Nov 2024rust-base64 version <= 0.5.1 is vulnerable to a buffer overflow when calculating the size of a buffer to use when encoding base64 using the 'encode_config_buf' and 'encode_config' functions
CVE-2017-1000424
Last Modified: 21 Nov 2024Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
CVE-2017-1000423
Last Modified: 21 Nov 2024b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.
CVE-2017-1000419
Last Modified: 21 Nov 2024phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.
CVE-2017-1000420
Last Modified: 21 Nov 2024Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
CVE-2017-1000421
Last Modified: 21 Nov 2024Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution
CVE-2017-1000457
Last Modified: 21 Nov 2024Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content Administrators" role.
CVE-2017-1000458
Last Modified: 21 Nov 2024Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation.
CVE-2017-1000451
Last Modified: 21 Nov 2024fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec.
CVE-2017-1000412
Last Modified: 21 Nov 2024Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.
CVE-2017-1000413
Last Modified: 21 Nov 2024Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.
CVE-2017-1000448
Last Modified: 21 Nov 2024Structured Data Linter versions 2.4.1 and older are vulnerable to a directory traversal attack in the URL input field resulting in the possibility of disclosing information about the remote host.
CVE-2017-1000449
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none
CVE-2017-1000452
Last Modified: 21 Nov 2024An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users.
CVE-2017-1000453
Last Modified: 21 Nov 2024CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.
CVE-2017-1000454
Last Modified: 21 Nov 2024CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1
CVE-2017-1000455
Last Modified: 21 Nov 2024GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.
CVE-2017-1557
Last Modified: 21 Nov 2024IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that could cause a channel process to cease processing further requests. IBM X-Force ID: 131547.
CVE-2017-1000444
Last Modified: 21 Nov 2024Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component resulting in information disclosure and remote code execution
CVE-2017-17098
Last Modified: 21 Nov 2024The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.
CVE-2017-17097
Last Modified: 21 Nov 2024gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.
CVE-2017-1000442
Last Modified: 21 Nov 2024Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
CVE-2017-1000443
Last Modified: 21 Nov 2024Eleix Openhacker version 0.1.47 is vulnerable to a XSS vulnerability in the bank transactions component resulting in arbitrary code execution in the browser.
CVE-2017-9966
Last Modified: 21 Nov 2024A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level.
CVE-2017-18015
Last Modified: 21 Nov 2024The ILLID Share This Image plugin before 1.04 for WordPress has XSS via the sharer.php url parameter.
CVE-2017-9964
Last Modified: 21 Nov 2024A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized person can execute a directory traversal attack resulting in authentication bypass or session hijack.
CVE-2017-9965
Last Modified: 21 Nov 2024An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.
CVE-2018-4756
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4757
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4758
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4759
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4760
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4761
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4762
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4763
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4764
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4765
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4766
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4767
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4768
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4770
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4771
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4772
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
CVE-2018-4773
Last Modified: 7 Nov 2023This candidate is unused by its CNA.
