Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In May 2017
dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during dumping of debug information from a corrupt binary. This vulnerability causes programs that conduct an analysis of binary programs, such as objdump and readelf, to crash.
CVSS Score
7.5
EPSS Score
0.004
Published
2017-05-01
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
CVSS Score
9.8
EPSS Score
0.027
Published
2017-05-01
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.
CVSS Score
5.4
EPSS Score
0.003
Published
2017-05-01
GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.
CVSS Score
8.8
EPSS Score
0.005
Published
2017-05-01
GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.
CVSS Score
5.3
EPSS Score
0.004
Published
2017-05-01
An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.
CVSS Score
7.5
EPSS Score
0.009
Published
2017-05-01
An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.
CVSS Score
6.1
EPSS Score
0.253
Published
2017-05-01
lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.
CVSS Score
9.1
EPSS Score
0.022
Published
2017-05-01
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
CVSS Score
5.3
EPSS Score
0.003
Published
2017-05-01
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-05-01


Contact Us

Shodan ® - All rights reserved