Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-12-20 CVE-2017-14819 Out-of-bounds Read vulnerability in Foxitsoftware Foxit Reader 8.3.1.21155
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155.
network
low complexity
foxitsoftware CWE-125
6.5
2017-12-20 CVE-2017-14818 Out-of-bounds Read vulnerability in Foxitsoftware Foxit Reader 8.3.1.21155
This vulnerability allows remote attackers to disclose sensitive on vulnerable installations of Foxit Reader 8.3.1.21155.
network
low complexity
foxitsoftware CWE-125
6.5
2017-12-20 CVE-2017-10956 Out-of-bounds Read vulnerability in Foxitsoftware Foxit Reader 8.3.1.21155
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155.
network
low complexity
foxitsoftware CWE-125
6.5
2017-12-20 CVE-2017-17792 Cross-site Scripting vulnerability in Blogotext Project Blogotext
Cross site scripting (XSS) vulnerability in the markup_clean_href function in inc/conv.php in BlogoText through 3.7.6 allows remote attackers to inject arbitrary JavaScript via a comment.
network
low complexity
blogotext-project CWE-79
6.1
2017-12-20 CVE-2017-17788 Out-of-bounds Read vulnerability in multiple products
In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
local
low complexity
gimp debian canonical CWE-125
5.5
2017-12-20 CVE-2017-17780 Cross-site Scripting vulnerability in Mediaburst products
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php.
network
low complexity
mediaburst CWE-79
6.1
2017-12-20 CVE-2017-17778 Cross-site Scripting vulnerability in Paid to Read Script Project Paid to Read Script 2.0.5
Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter.
network
low complexity
paid-to-read-script-project CWE-79
4.8
2017-12-20 CVE-2017-17776 Information Exposure vulnerability in Paid to Read Script Project Paid to Read Script 2.0.5
Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter.
network
low complexity
paid-to-read-script-project CWE-200
5.3
2017-12-20 CVE-2017-17775 Cross-site Scripting vulnerability in Piwigo 2.9.2
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
network
low complexity
piwigo CWE-79
6.1
2017-12-19 CVE-2017-17753 Cross-site Scripting vulnerability in Csv-Import-Export Project Csv-Import-Export 1.0.0
Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cie_type, (2) cie_import, (3) cie_update, or (4) cie_ignore parameter to includes/admin/views/esb-cie-import-export-page.php.
network
low complexity
csv-import-export-project CWE-79
6.1