Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In January 2017
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user_prefs.lua, admin/delete_user.lua, and admin/password_reset.lua.
CVSS Score
8.8
EPSS Score
0.001
Published
2017-01-14
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-01-14
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
CVSS Score
8.8
EPSS Score
0.001
Published
2017-01-14
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
CVSS Score
8.8
EPSS Score
0.001
Published
2017-01-14
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.
CVSS Score
8.8
EPSS Score
0.015
Published
2017-01-13
The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted series of skip and count pairs.
CVSS Score
7.5
EPSS Score
0.072
Published
2017-01-13
Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.
CVSS Score
7.8
EPSS Score
0.005
Published
2017-01-13
The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref call.
CVSS Score
5.5
EPSS Score
0.007
Published
2017-01-13
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
CVSS Score
4.7
EPSS Score
0.005
Published
2017-01-13
The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section.
CVSS Score
7.5
EPSS Score
0.014
Published
2017-01-13


Contact Us

Shodan ® - All rights reserved