CVE-2017-15574
- EPSS 0.38%
- Veröffentlicht 18.10.2017 02:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Redmine before 3.2.6 and 3.3.x before 3.3.3, stored XSS is possible by using an SVG document as an attachment.
CVE-2017-15575
- EPSS 0.72%
- Veröffentlicht 18.10.2017 02:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Redmine before 3.2.6 and 3.3.x before 3.3.3, Redmine.pm lacks a check for whether the Repository module is enabled in a project's settings, which might allow remote attackers to obtain sensitive differences information or possibly have unspecified...
CVE-2017-15576
- EPSS 0.54%
- Veröffentlicht 18.10.2017 02:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.
CVE-2017-15577
- EPSS 0.54%
- Veröffentlicht 18.10.2017 02:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information.
CVE-2017-15565
- EPSS 0.62%
- Veröffentlicht 17.10.2017 22:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.
CVE-2017-13078
- EPSS 0.7%
- Veröffentlicht 17.10.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.
CVE-2017-13079
- EPSS 0.35%
- Veröffentlicht 17.10.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.
CVE-2017-13080
- EPSS 0.82%
- Veröffentlicht 17.10.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
CVE-2017-13081
- EPSS 0.34%
- Veröffentlicht 17.10.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.
CVE-2017-13082
- EPSS 0.69%
- Veröffentlicht 17.10.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, ...