Latest CVE Feed
-
9.8
CRITICALCVE-2017-2520
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "SQLite" component. It allows remote attackers to ... Read more
- EPSS Score: %2.45
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9169
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:355:25.... Read more
Affected Products : autotrace- EPSS Score: %0.51
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9265
In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_ofp15_group_mod`.... Read more
Affected Products : openvswitch- EPSS Score: %1.54
- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9433
Document Liberation Project libmwaw before 2017-04-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the MsWrd1Parser::readFootnoteCorrespondance function in lib/MsWrd1Parser.cxx.... Read more
Affected Products : libmwaw- EPSS Score: %0.54
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-6551
The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region ... Read more
Affected Products : glibc- EPSS Score: %0.42
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-5336
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.... Read more
- EPSS Score: %3.94
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5446
An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox... Read more
- EPSS Score: %1.43
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-2090
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.... Read more
- EPSS Score: %1.94
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6182
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.... Read more
- EPSS Score: %14.26
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2141
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within ... Read more
- EPSS Score: %0.88
- Published: Jun. 30, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2017-17434
The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism t... Read more
- EPSS Score: %1.16
- Published: Dec. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-0036
When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", "internal-2", etc.) are silently ignored. No warning is issued during configuration, and the config is committed without error, but the... Read more
Affected Products : junos- EPSS Score: %0.26
- Published: Apr. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10137
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the ... Read more
- EPSS Score: %8.94
- Published: Jul. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7786
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.... Read more
- EPSS Score: %11.01
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7863
FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.... Read more
- EPSS Score: %1.88
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-12805
Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability. Successful exploitation could lead to privilege escalation.... Read more
Affected Products : connect- EPSS Score: %2.50
- Published: Jul. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-11068
libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequ... Read more
Affected Products : ubuntu_linux fedora debian_linux leap active_iq_unified_manager cloud_backup hci_management_node solidfire oncommand_insight oncommand_workflow_automation +13 more products- EPSS Score: %0.93
- Published: Apr. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-8816
The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vecto... Read more
- EPSS Score: %0.62
- Published: Nov. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2019-11831
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.ph... Read more
- EPSS Score: %3.02
- Published: May. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-9264
In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered ... Read more
Affected Products : openvswitch- EPSS Score: %0.78
- Published: May. 29, 2017
- Modified: Apr. 20, 2025