Latest CVE Feed
-
9.8
CRITICALCVE-2017-7375
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a... Read more
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-7351
A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.... Read more
- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7342
A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via a hidden Close button... Read more
Affected Products : fortiportal- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-7340
A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.... Read more
Affected Products : fortiportal- Published: Mar. 25, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-7327
Yandex Browser installer for Desktop before 17.4.1 has a DLL Hijacking Vulnerability because an untrusted search path is used for dnsapi.dll, winmm.dll, ntmarta.dll, cryptbase.dll or profapi.dll.... Read more
Affected Products : yandex_browser- Published: Jan. 19, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-7326
Race condition issue in Yandex Browser for Android before 17.4.0.16 allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page... Read more
Affected Products : yandex_browser- Published: Jan. 19, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-7325
Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.... Read more
Affected Products : yandex_browser- Published: Jan. 19, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-7252
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.... Read more
Affected Products : botan- Published: Nov. 03, 2023
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-7189
main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127.0.0.1:80', 443) as if the address/port were 127.0.0.1:80:443, which is later truncated to 127.0.0.1:80. This behavior has a security ri... Read more
Affected Products : php- Published: Jul. 10, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-7173
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-7172
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is af... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-7171
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "CoreAnimation" component. It allows attackers to execut... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-7170
An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Security" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-7167
An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves the "ld64" component. A buffer overflow allows remote attackers to execute arbitrary code via crafted source code.... Read more
Affected Products : xcode- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-7165
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is af... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2017-7164
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. The issue involves the "App Store" component. It allows man-in-the-middle attackers to spoof password prompts.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-7161
An issue was discovered in certain Apple products. Safari before 11.0.2 is affected. The issue involves the "WebKit Web Inspector" component. It allows remote attackers to execute arbitrary code via special characters that trigger command injection.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-7153
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is af... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2017-7151
A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Sierra 10.13.2, tvOS 11.2, watchOS 4.2, iTunes 12.7.2 for Windows, macOS High Sierra 10.13.4.... Read more
- Published: Apr. 03, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-7075
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Notes" component. It allows local users to obtain sensitive information by reading search results that contain locked-note content.... Read more
Affected Products : iphone_os- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024