CVE-2017-16852
- EPSS 0.32%
- Veröffentlicht 16.11.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as si...
CVE-2017-16853
- EPSS 0.69%
- Veröffentlicht 16.11.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as ...
CVE-2017-15864
- EPSS 0.5%
- Veröffentlicht 16.11.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password.
CVE-2017-8807
- EPSS 1.75%
- Veröffentlicht 16.11.2017 02:29:05
- Zuletzt bearbeitet 20.04.2025 01:37:25
vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in cer...
CVE-2017-15115
- EPSS 0.04%
- Veröffentlicht 15.11.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possi...
CVE-2017-15923
- EPSS 1.48%
- Veröffentlicht 15.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing of IRC color formatting codes.
CVE-2017-8808
- EPSS 0.4%
- Veröffentlicht 15.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping.
CVE-2017-8809
- EPSS 18.08%
- Veröffentlicht 15.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
CVE-2017-8810
- EPSS 0.96%
- Veröffentlicht 15.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumera...
CVE-2017-8811
- EPSS 0.33%
- Veröffentlicht 15.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks.