Unknown · CVSS Not scored
The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter.
Published Sep 13, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page parameter.
Published Sep 10, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
Published Sep 16, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
Published Sep 25, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The avada theme before 5.1.5 for WordPress has CSRF.
Published Sep 10, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The examapp plugin 1.0 for WordPress has XSS via exam input text fields.
Published Sep 10, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
Published Sep 10, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues.
Published Sep 10, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-tables-admin.php tableId parameter.
Published Sep 10, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Small Cell SoC and Snapdragon (Automobile, Mobile, Wear) in version FSM9055, FSM9955, MDM9607, MDM9640, MDM9650, MSM8909W, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SDM630, SDM636, SDM660, SDX20, Snapdragon_High_Med_2016, providing the NULL argument of ICE regulator while processing create key IOCTL results in system restart.
Published Sep 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions.
Published Sep 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, on TZ cold boot the CNOC_QDSS RG0 locked by xBL_SEC is cleared by TZ.
Published Sep 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDM429, SDM439, SDM632, Snapdragon_High_Med_2016, when a Trusted Application has opened the SPI/I2C interface to a particular device, it is possible for another Trusted Application to read the data on this open interface by calling the SPI/I2C read function.
Published Sep 20, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a man in the middle attack.
Published Sep 7, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
Published Sep 25, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger this vulnerability.
Published Sep 14, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while loading a user application in qseecom, an integer overflow could potentially occur if the application partition size is rounded up to page_size.
Published Sep 18, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the function for writing device values into flash, uninitialized memory can be written to flash.
Published Sep 18, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while accessing the keystore in LK, an integer overflow vulnerability exists which may potentially lead to a buffer overflow.
Published Sep 18, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing a gpt update, an out of bounds memory access may potentially occur.
Published Sep 18, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
Published Sep 26, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ExifImageFile::readDQT in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted JPEG file.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
_bfd_elf_slurp_version_tables in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Stored XSS vulnerability via IMG element at "Leadname" of CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application administrator and other users.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc infinite loop), a different vulnerability than CVE-2017-14519.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a heap-based buffer overflow in the Exiv2::s2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.
Published Sep 28, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Memory leak in decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive information.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
Published Sep 28, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with an IMG element, related to tiki-objectpermissions.php. For example, an attacker could assign administrator privileges to every unauthenticated user of the site.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calculation, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to read_1_byte.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Stored XSS vulnerability via IMG element at "History" of Profile, Calendar, Tasks, and CRM in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application administrator and other users.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
Published Sep 28, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Stored XSS vulnerability via IMG element at "Filename" of Filemanager in Tine 2.0 Community Edition before 2017.08.4 allows an authenticated user to inject JavaScript, which is mishandled during rendering by the application administrator and other users.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a denial of service attack.
Published Sep 28, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.
Published Sep 28, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.
Published Sep 28, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
Published Sep 27, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to gain administrator privileges if an administrator opens a wiki page with an IMG element, related to tiki-assignuser.php.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
Published Sep 27, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file that contains a negative size value in a CU structure.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
Published Sep 28, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.
Published Sep 29, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.
Published Sep 28, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
Published Sep 28, 2017 · Updated Aug 5, 2024