Latest CVE Feed
-
8.1
HIGHCVE-2017-6363
In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, an... Read more
Affected Products : libgd- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2017-6323
The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclos... Read more
Affected Products : management_console- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2017-6296
NVIDIA TrustZone Software contains a TOCTOU issue in the DRM application which may lead to the denial of service or possible escalation of privileges. This issue is rated as moderate.... Read more
- Published: Mar. 06, 2018
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2017-6295
NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or information disclosure. This issue is rate... Read more
- Published: Mar. 06, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-6294
In Android before the 2018-06-05 security patch level, NVIDIA Tegra X1 TZ contains a possible out of bounds write due to missing bounds check which could lead to escalation of privilege from the kernel to the TZ. User interaction is not needed for exploit... Read more
Affected Products : android- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-6293
In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. Thi... Read more
Affected Products : android- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-6292
In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due to integer overflow which could lead to local escalation of privilege in the TrustZone with no additional execution privileges needed. ... Read more
Affected Products : android- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-6290
In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due to an integer overflow which could lead to local escalation of privilege with no additional execution privileges needed. User interacti... Read more
Affected Products : android- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-6289
In Android before the 2018-05-05 security patch level, NVIDIA Trusted Execution Environment (TEE) contains a memory corruption (due to unusual root cause) vulnerability, which if run within the speculative execution of the TEE, may lead to local escalatio... Read more
Affected Products : android- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-6288
NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate. Product: Android. Version: N/A. Android: A-65482562. Reference: N-CVE-2017-6288.... Read more
Affected Products : android- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-6287
NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate.Product: Android. Version: N/A. Android: A-64893264. Reference: N-CVE-2017-6287.... Read more
Affected Products : android- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-6286
NVIDIA libnvomx contains a possible out of bounds write due to a missing bounds check which could lead to local escalation of privilege. This issue is rated as high. Product: Android. Version: N/A. Android: A-64893247. Reference: N-CVE-2017-6286.... Read more
Affected Products : android- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-6285
NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local information disclosure. This issue is rated as moderate. Product: Android. Version: N/A. Android: A-64893156. Reference: N-CVE-2017-6285.... Read more
Affected Products : android- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-6284
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive data ... Read more
- Published: Mar. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-6283
NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cleared on a chip reset which may lead to information disclosure. This issue is rated as high.... Read more
- Published: Mar. 06, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-6282
NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as high.... Read more
- Published: Mar. 06, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-6281
NVIDIA libnvomx contains a possible out of bounds write due to a improper input validation which could lead to local escalation of privilege. This issue is rated as high. Product: Android. Version: N/A. Android: A-66969318. Reference: N-CVE-2017-6281.... Read more
Affected Products : android- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-6280
NVIDIA driver contains a possible out-of-bounds read vulnerability due to a leak which may lead to information disclosure. This issue is rated as moderate. Android: A-63851980.... Read more
Affected Products : android- Published: Mar. 06, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-6279
NVIDIA libnvmmlite_audio.so contains an elevation of privilege vulnerability when running in media server which may cause an out of bounds write and could lead to local code execution in a privileged process. This issue is rated as high. Product: Android.... Read more
Affected Products : android- Published: Feb. 06, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-6278
NVIDIA Tegra kernel contains a vulnerability in the CORE DVFS Thermal driver where there is the potential to read or write a buffer using an index or pointer that references a memory location after the end of the buffer, which may lead to a denial of serv... Read more
Affected Products : jetson_tx1_firmware jetson_tk1_firmware tegra_k1_firmware jetson_tx1 jetson_tk1 tegra_k1- Published: Mar. 26, 2018
- Modified: Nov. 21, 2024