Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2017
The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote attackers to cause a denial of service (incorrect malloc and heap-based buffer overflow) or possibly have unspecified other impact via a crafted file.
CVSS Score
7.8
EPSS Score
0.012
Published
2017-11-12
The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as demonstrated by an erroneous png_load call that occurs because of incorrect integer data types in png2swf.
CVSS Score
5.5
EPSS Score
0.01
Published
2017-11-12
Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.
CVSS Score
7.5
EPSS Score
0.011
Published
2017-11-11
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
CVSS Score
9.8
EPSS Score
0.058
Published
2017-11-10
The installer in MyBB before 1.8.13 has XSS.
CVSS Score
5.4
EPSS Score
0.016
Published
2017-11-10
In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.
CVSS Score
6.1
EPSS Score
0.008
Published
2017-11-10
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
CVSS Score
9.8
EPSS Score
0.08
Published
2017-11-10
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
CVSS Score
6.1
EPSS Score
0.007
Published
2017-11-10
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
CVSS Score
6.1
EPSS Score
0.01
Published
2017-11-10
XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.
CVSS Score
6.1
EPSS Score
0.01
Published
2017-11-10


Contact Us

Shodan ® - All rights reserved