CVE-2017-15864
- EPSS 0.5%
- Veröffentlicht 16.11.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password.
CVE-2017-8807
- EPSS 1.75%
- Veröffentlicht 16.11.2017 02:29:05
- Zuletzt bearbeitet 20.04.2025 01:37:25
vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a VFP_GetStorage buffer is larger than intended in cer...
CVE-2017-15115
- EPSS 0.04%
- Veröffentlicht 15.11.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possi...
CVE-2017-15923
- EPSS 1.48%
- Veröffentlicht 15.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing of IRC color formatting codes.
CVE-2017-8808
- EPSS 0.4%
- Veröffentlicht 15.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping.
CVE-2017-8809
- EPSS 18.08%
- Veröffentlicht 15.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
CVE-2017-8810
- EPSS 0.96%
- Veröffentlicht 15.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumera...
CVE-2017-8811
- EPSS 0.33%
- Veröffentlicht 15.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks.
CVE-2017-8812
- EPSS 0.83%
- Veröffentlicht 15.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline.
CVE-2017-8814
- EPSS 0.65%
- Veröffentlicht 15.11.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."