Latest CVE Feed
-
5.5
MEDIUMCVE-2017-3053
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the image conversion engine, related to parsing of the APP13 segment in JPEG files.... Read more
- EPSS Score: %4.48
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-18226
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script exe... Read more
- EPSS Score: %0.03
- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18183
An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.... Read more
Affected Products : qpdf- EPSS Score: %0.32
- Published: Feb. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-15939
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application... Read more
Affected Products : binutils- EPSS Score: %0.34
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15298
Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process ... Read more
- EPSS Score: %0.43
- Published: Oct. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15022
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the DW_AT_name data type, which allows remote attackers to cause a denial of service (bfd_hash_hash NULL pointer dereference, or out-... Read more
Affected Products : binutils- EPSS Score: %0.45
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14938
_bfd_elf_slurp_version_tables in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted EL... Read more
Affected Products : binutils- EPSS Score: %0.53
- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-13822
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Quick Look" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.... Read more
- EPSS Score: %0.20
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-13694
The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel ... Read more
Affected Products : linux_kernel- EPSS Score: %0.05
- Published: Aug. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-12141
In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.... Read more
Affected Products : ytnef- EPSS Score: %0.17
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11934
Microsoft Office 2013 RT SP1, Microsoft Office 2013 SP1, and Microsoft Office 2016 allow an information disclosure vulnerability due to the way certain functions handle objects in memory, aka "Microsoft Office Information Disclosure Vulnerability".... Read more
Affected Products : office- EPSS Score: %12.12
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11732
A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.... Read more
- EPSS Score: %0.22
- Published: Jul. 29, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10365
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple prot... Read more
- EPSS Score: %0.31
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1000126
exiv2 0.26 contains a Stack out of bounds read in webp parser... Read more
Affected Products : exiv2- EPSS Score: %0.32
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0295
Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAULT folder structure, aka "Windows Default Folder Tampering Vulnerability".... Read more
- EPSS Score: %0.53
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9827
The _iprintf function in outputtxt.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of service (buffer over-read) via a crafted SWF file.... Read more
Affected Products : libming- EPSS Score: %0.22
- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9810
The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref ca... Read more
Affected Products : gstreamer- EPSS Score: %0.66
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9642
JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.... Read more
Affected Products : webkit- EPSS Score: %0.19
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9392
The calcstepsizes function in jpc_dec.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.... Read more
Affected Products : jasper- EPSS Score: %0.47
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9191
The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted applicati... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Nov. 28, 2016
- Modified: Apr. 12, 2025