CVE-2017-11361
Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the...
Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the...
The ReadRLEImage function in codersrle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge number_pixels value. Date published : 2017-07-17 https://github.com/ImageMagick/ImageMagick/issues/518
Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name. Date published : 2017-07-17 https://github.com/FiyoCMS/FiyoCMS/issues/4
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry. Date published : 2017-07-17 https://websecnerd.blogspot.in/2017/07/bolt-cms-3.html
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header. Date published : 2017-07-17 https://websecnerd.blogspot.in/2017/07/bolt-cms-3.html
An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP – Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service. Date published : 2017-07-17 http://www.securityfocus.com/bid/99970 http://freeradius.org/security/fuzzer-2017.html
An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP – Infinite read in dhcp_attr2vp()" and a denial of service. Date published : 2017-07-17 http://www.securityfocus.com/bid/99971 http://freeradius.org/security/fuzzer-2017.html
An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with ‘concat’ attributes" and a denial of service. Date published : 2017-07-17 http://www.securityfocus.com/bid/99968 http://freeradius.org/security/fuzzer-2017.html
An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" – this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code. Date published :...
An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP – Read overflow when decoding option 63" and a denial of service. Date published : 2017-07-17 http://www.securityfocus.com/bid/99915 http://freeradius.org/security/fuzzer-2017.html
An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP – Buffer over-read in fr_dhcp_decode_options()" and a denial of service. Date published : 2017-07-17 http://www.securityfocus.com/bid/99912 http://freeradius.org/security/fuzzer-2017.html
An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP – Memory leak in fr_dhcp_decode()" and a denial of service. Date published : 2017-07-17 http://www.securityfocus.com/bid/99898 http://freeradius.org/security/fuzzer-2017.html
An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP – Memory leak in decode_tlv()" and a denial of service. Date published : 2017-07-17 http://www.securityfocus.com/bid/99905 http://freeradius.org/security/fuzzer-2017.html
An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" – this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code. Date published :...