Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 892

Количество 79 892

ubuntu логотип

CVE-2017-1002201

почти 7 лет назад

In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-1002153

почти 9 лет назад

Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-1002150

около 9 лет назад

python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-1002102

больше 8 лет назад

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2017-1002101

больше 8 лет назад

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2017-1001001

почти 9 лет назад

PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-1001000

больше 9 лет назад

The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value and a non-numeric value, as demonstrated by the wp-json/wp/v2/posts/123?id=123helloworld URI.

CVSS3: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2017-1000

больше 3 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

EPSS: Низкий
ubuntu логотип

CVE-2017-1000600

около 8 лет назад

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000509

больше 8 лет назад

Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-1000501

больше 8 лет назад

Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000499

больше 8 лет назад

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000494

больше 8 лет назад

Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000487

больше 8 лет назад

Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000480

больше 8 лет назад

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000476

больше 8 лет назад

ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-1000472

больше 8 лет назад

The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompression, and possibly create or overwrite arbitrary files, via a crafted ZIP file, related to a "file path injection vulnerability".

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-1000469

больше 8 лет назад

Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000460

больше 8 лет назад

In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-1000458

больше 8 лет назад

Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-1002201

In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.

CVSS3: 6.1
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2017-1002153

Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.

CVSS3: 7.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-1002150

python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection

CVSS3: 6.1
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-1002102

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

CVSS3: 7.1
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1002101

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.

CVSS3: 8.8
13%
Средний
больше 8 лет назад
ubuntu логотип
CVE-2017-1001001

PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.

CVSS3: 5.4
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-1001000

The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value and a non-numeric value, as demonstrated by the wp-json/wp/v2/posts/123?id=123helloworld URI.

CVSS3: 7.5
85%
Высокий
больше 9 лет назад
ubuntu логотип
CVE-2017-1000

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none.

больше 3 лет назад
ubuntu логотип
CVE-2017-1000600

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9

CVSS3: 8.8
3%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2017-1000509

Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.

CVSS3: 5.4
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000501

Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.

CVSS3: 9.8
4%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000499

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

CVSS3: 8.8
9%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000494

Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact

CVSS3: 7.8
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000487

Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.

CVSS3: 9.8
6%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000480

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.

CVSS3: 9.8
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000476

ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.

CVSS3: 6.5
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000472

The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompression, and possibly create or overwrite arbitrary files, via a crafted ZIP file, related to a "file path injection vulnerability".

CVSS3: 6.5
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000469

Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.

CVSS3: 9.8
5%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000460

In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000458

Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation.

CVSS3: 9.8
2%
Низкий
больше 8 лет назад

Уязвимостей на страницу