Latest CVE Feed
-
9.8
CRITICALCVE-2017-14648
A global buffer overflow was discovered in the iteration_loop function in loop.c in BladeEnc version 0.94.2. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.... Read more
Affected Products : bladeenc- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14698
ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote attackers to change passwords of arbitrary use... Read more
Affected Products : dsl-n12e_c1_firmware dsl-n17u_firmware dsl-n14u-b1_firmware dsl-ac51_firmware dsl-ac52u_firmware dsl-ac55u_firmware dsl-n55u_c1_firmware dsl-n55u_d1_firmware dsl-ac56u_firmware dsl-n10_c1_firmware +22 more products- Published: Jan. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-44350
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.... Read more
Affected Products : coldfusion- Published: Nov. 17, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-14636
Because of an integer overflow in sam2p 0.49.3, a loop executes 0xffffffff times, ending with an invalid read of size 1 in the Image::Indexed::sortPal function in image.cpp. However, this also causes memory corruption because of an attempted write to the ... Read more
Affected Products : sam2p- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14695
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NO... Read more
Affected Products : salt- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14631
In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer overflow.... Read more
Affected Products : sam2p- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14630
In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid write operation.... Read more
Affected Products : sam2p- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14626
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_decode in coders/sixel.c.... Read more
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14586
The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at or above version 4.0 and before version 4.30 are affected by this vulnerability.... Read more
Affected Products : hipchat- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14596
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.... Read more
Affected Products : joomla\!- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14628
In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp.... Read more
Affected Products : sam2p- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-41361
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.... Read more
- Published: Aug. 29, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-14625
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_create in coders/sixel.c.... Read more
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14507
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timel... Read more
Affected Products : content_timeline- Published: Sep. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14512
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.... Read more
Affected Products : nexusphp- Published: Sep. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2023-39143
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).... Read more
- Published: Aug. 04, 2023
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2017-14417
register_send.php on D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices does not require authentication, which can result in unintended enrollment in mydlink Cloud Services.... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14351
A potential security vulnerability has been identified in HP UCMDB Configuration Manager versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.23. These vulnerabilities could be remotely exploited to allow code execution.... Read more
Affected Products : ucmdb_configuration_manager- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14346
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.... Read more
- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14323
SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile parameter.... Read more
Affected Products : onethink- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024