Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2017
In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.
CVSS Score
4.3
EPSS Score
0.002
Published
2017-11-20
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.
CVSS Score
7.5
EPSS Score
0.858
Published
2017-11-20
In Bftpd before 4.7, there is a memory leak in the file rename function.
CVSS Score
7.5
EPSS Score
0.003
Published
2017-11-19
Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account, a related issue to CVE-2017-14312. This also affects bin/icingastats, bin/ido2db, and bin/log2ido.
CVSS Score
7.8
EPSS Score
0.0
Published
2017-11-18
The outputSWF_TEXT_RECORD function in util/outputscript.c in libming <= 0.4.8 is vulnerable to a NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted swf file.
CVSS Score
6.5
EPSS Score
0.003
Published
2017-11-18
b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL value to /settings/avatar, related to processor/AdminProcessor.java, processor/ArticleProcessor.java, processor/UserProcessor.java, service/ArticleQueryService.java, service/AvatarQueryService.java, and service/CommentQueryService.java.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-11-18
HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_USER_AGENT'] parameter to example_form.ajax.php or example_form.php.
CVSS Score
6.1
EPSS Score
0.002
Published
2017-11-18
On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core system files including those used for authentication (such as passwd and shadow). This can be abused to take full root level control of the device.
CVSS Score
9.8
EPSS Score
0.013
Published
2017-11-17
exiv2 0.26 contains a Stack out of bounds read in webp parser
CVSS Score
5.5
EPSS Score
0.003
Published
2017-11-17
Exiv2 0.26 contains a heap buffer overflow in tiff parser
CVSS Score
5.5
EPSS Score
0.004
Published
2017-11-17


Contact Us

Shodan ® - All rights reserved