CVE-2017-15573
- EPSS 0.38%
- Veröffentlicht 18.10.2017 02:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Redmine before 3.2.6 and 3.3.x before 3.3.3, XSS exists because markup is mishandled in wiki content.
CVE-2017-15574
- EPSS 0.38%
- Veröffentlicht 18.10.2017 02:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
CVE-2017-15575
- EPSS 0.72%
- Veröffentlicht 18.10.2017 02:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified...
CVE-2017-15576
- EPSS 0.54%
- Veröffentlicht 18.10.2017 02:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
CVE-2017-15577
- EPSS 0.54%
- Veröffentlicht 18.10.2017 02:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
CVE-2017-15565
- EPSS 0.62%
- Veröffentlicht 17.10.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.
CVE-2017-13078
- EPSS 0.71%
- Veröffentlicht 17.10.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.
CVE-2017-13079
- EPSS 0.35%
- Veröffentlicht 17.10.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.
CVE-2017-13080
- EPSS 0.63%
- Veröffentlicht 17.10.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
CVE-2017-13081
- EPSS 0.34%
- Veröffentlicht 17.10.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.