Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-03 CVE-2017-1000484 Open Redirect vulnerability in Plone
By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website.
network
low complexity
plone CWE-601
6.1
2018-01-03 CVE-2017-1000472 Path Traversal vulnerability in multiple products
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompression, and possibly create or overwrite arbitrary files, via a crafted ZIP file, related to a "file path injection vulnerability".
network
low complexity
pocoproject debian CWE-22
6.5
2018-01-03 CVE-2017-1000462 Cross-site Scripting vulnerability in Bookstackapp Bookstack 0.18.4
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.
network
low complexity
bookstackapp CWE-79
5.4
2018-01-03 CVE-2017-1000461 Incorrect Permission Assignment for Critical Resource vulnerability in Brave Browser 0.19.73
Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fingerprinting-associated browser functionality (that the browser intends to block).
network
low complexity
brave CWE-732
4.7
2018-01-03 CVE-2017-1000460 NULL Pointer Dereference vulnerability in multiple products
In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.
network
low complexity
libav ffmpeg google CWE-476
6.5
2018-01-03 CVE-2017-1000483 Unspecified vulnerability in Plone
Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1.
network
low complexity
plone
6.5
2018-01-03 CVE-2017-1000482 Cross-site Scripting vulnerability in Plone
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
network
low complexity
plone CWE-79
5.4
2018-01-03 CVE-2017-1000481 Open Redirect vulnerability in Plone
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url.
network
low complexity
plone CWE-601
6.1
2018-01-03 CVE-2017-1000478 Cross-site Scripting vulnerability in Elabftw 1.7.8
ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript and denial of service.
network
low complexity
elabftw CWE-79
5.4
2018-01-03 CVE-2017-1000476 Resource Exhaustion vulnerability in multiple products
ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.
network
low complexity
imagemagick debian canonical CWE-400
6.5