Show filters
199 Total Results
Displaying 51-60 of 199
Sort by:
Attacker Value
Unknown

CVE-2017-8815

Disclosure Date: November 15, 2017 (last updated November 26, 2024)
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules.
0
Attacker Value
Unknown

CVE-2017-8809

Disclosure Date: November 15, 2017 (last updated November 26, 2024)
api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.
0
Attacker Value
Unknown

CVE-2017-8811

Disclosure Date: November 15, 2017 (last updated November 26, 2024)
The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling attacks.
0
Attacker Value
Unknown

CVE-2017-8808

Disclosure Date: November 15, 2017 (last updated November 26, 2024)
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting is false and the browser sends non-standard URL escaping.
0
Attacker Value
Unknown

CVE-2017-8810

Disclosure Date: November 15, 2017 (last updated November 26, 2024)
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests.
0
Attacker Value
Unknown

CVE-2017-8814

Disclosure Date: November 15, 2017 (last updated November 26, 2024)
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."
0
Attacker Value
Unknown

CVE-2017-16651

Disclosure Date: November 09, 2017 (last updated November 26, 2024)
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
Attacker Value
Unknown

CVE-2017-15954

Disclosure Date: October 28, 2017 (last updated November 26, 2024)
bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processing a malformed CUE (.cue) file.
0
Attacker Value
Unknown

CVE-2017-15955

Disclosure Date: October 28, 2017 (last updated November 26, 2024)
bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on destination operand" and crash when processing a malformed CUE (.cue) file.
0
Attacker Value
Unknown

CVE-2017-15953

Disclosure Date: October 28, 2017 (last updated November 26, 2024)
bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file.
0