CVE-2017-9773

CVSS v3 Score
5.7
Medium
CVSS v2 Score
4.3
Medium

Vulnerability Description

Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver.

CVSS:5.7(Medium)

LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displa...

CWE-202016
CVSS:5.7(Medium)

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

CWE-202016
CVSS:5.7(Medium)

IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicio...

CWE-202016
CVSS:5.7(Medium)

In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user's intention only if attacker can reveal the Bluetoo...

CWE-202017
CVSS:5.7(Medium)

An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found.

CWE-202017
CVSS:5.7(Medium)

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.

CWE-202018