Latest CVE Feed
-
8.8
HIGHCVE-2017-5133
Off-by-one read/write on the heap in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to corrupt memory and possibly leak information and potentially execute code via a crafted PDF file.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-5132
Inappropriate implementation in V8 in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka incorrect WebAssembly stack manipulation.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-5131
An integer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an out-of-bounds write.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-5130
An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-5129
A use after free in WebAudio in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-5128
Heap buffer overflow in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, related to WebGL.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-5127
Use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-5126
A use after free in PDFium in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-5125
Heap buffer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-5124
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted MHTML page.... Read more
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-5123
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.... Read more
Affected Products : linux_kernel cloud_backup h300s_firmware h500s_firmware h700s_firmware h410s_firmware h300s h410s h500s h700s +6 more products- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-5028
Insufficient data validation in V8 in Google Chrome prior to 56.0.2924.76 allowed a remote attacker to leak cross-origin data via a crafted HTML page.... Read more
Affected Products : chrome- Published: Jun. 27, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-4952
VMware Xenon 1.x, prior to 1.5.4-CR7_1, 1.5.7_7, 1.5.4-CR6_2, 1.3.7-CR1_2, 1.1.0-CR0-3, 1.1.0-CR3_1,1.4.2-CR4_1, and 1.5.4_8, contains an authentication bypass vulnerability due to insufficient access controls for utility endpoints. Successful exploitatio... Read more
Affected Products : xenon- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-4951
VMware AirWatch Console (9.2.x before 9.2.2 and 9.1.x before 9.1.5) contains a Cross Site Request Forgery vulnerability when accessing the App Catalog. An attacker may exploit this issue by tricking users into installing a malicious application on their d... Read more
- Published: Jan. 29, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2017-4950
VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an out-of-bound read which can then be used to execute code on the host in conjunction with other issues. Note:... Read more
- Published: Jan. 11, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2017-4949
VMware Workstation and Fusion contain a use-after-free vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may allow a guest to execute code on the host. Note: IPv6 mode for VMNAT is not enabled by default.... Read more
- Published: Jan. 11, 2018
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2017-4948
VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a guest to leak information from hos... Read more
- Published: Jan. 05, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-4947
VMware vRealize Automation (7.3 and 7.2) and vSphere Integrated Containers (1.x before 1.3) contain a deserialization vulnerability via Xenon. Successful exploitation of this issue may allow remote attackers to execute arbitrary code on the appliance.... Read more
- Published: Jan. 29, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-4946
The VMware V4H and V4PA desktop agents (6.x before 6.5.1) contain a privilege escalation vulnerability. Successful exploitation of this issue could result in a low privileged windows user escalating their privileges to SYSTEM.... Read more
- Published: Jan. 05, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-4945
VMware Workstation (14.x and 12.x) and Fusion (10.x and 8.x) contain a guest access control vulnerability. This issue may allow program execution via Unity on locked Windows VMs. VMware Tools must be updated to 10.2.0 for each VM to resolve CVE-2017-4945.... Read more
- Published: Jan. 05, 2018
- Modified: Nov. 21, 2024