Latest CVE Feed
-
7.5
HIGHCVE-2017-2852
An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out-of-bounds read, resulting in a denial of service. An attacker can send a m... Read more
Affected Products : xltek_neuroworks- Published: Jun. 01, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-2840
A buffer overflow vulnerability exists in the ISO parsing functionality of EZB Systems UltraISO 9.6.6.3300. A specially crafted .ISO file can cause a vulnerability resulting in potential code execution. An attacker can provide a specific .ISO file to trig... Read more
Affected Products : ultraiso- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-2839
An exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker c... Read more
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-2838
An exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker c... Read more
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-2837
An exploitable denial of service vulnerability exists within the handling of security data in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can c... Read more
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-2836
An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. ... Read more
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-2835
An exploitable code execution vulnerability exists in the RDP receive functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise th... Read more
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-2834
An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise... Read more
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-2833
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters... Read more
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2017-2832
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters... Read more
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2826
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information d... Read more
- Published: Apr. 09, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2017-2825
In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabb... Read more
- Published: Apr. 20, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2017-2815
An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the retrieval of arbitrary files or denial of service. An authenticated attacker can send a crafted web request... Read more
Affected Products : user_import_export- Published: May. 15, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-2812
A code execution vulnerability exists in the kdu_buffered_expand function of the Kakadu SDK 7.9. A specially crafted JPEG 2000 file can be read by the program and can lead to an out of bounds write causing an exploitable condition to arise.... Read more
Affected Products : kakadu_sdk- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-2811
A code execution vulnerability exists in the Kakadu SDK 7.9's parsing of compressed JPEG 2000 images. A specially crafted JPEG 2000 file can be read by the program, and can lead to an out of bounds write causing an exploitable condition to arise.... Read more
Affected Products : kakadu_sdk- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-2804
A remote out of bound write vulnerability exists in the TIFF parsing functionality of Core PHOTO-PAINT X8 18.1.0.661. A specially crafted TIFF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a speci... Read more
Affected Products : coreldraw_photo_paint_x8- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-2803
A remote out of bound write vulnerability exists in the TIFF parsing functionality of Core PHOTO-PAINT X8 version 18.1.0.661. A specially crafted TIFF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim... Read more
Affected Products : coreldraw_photo_paint_x8- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-2802
An exploitable dll hijacking vulnerability exists in the poaService.exe service component of the Dell Precision Optimizer software version 3.5.5.0. A specifically named malicious dll file located in one of directories pointed to by the PATH environment va... Read more
Affected Products : precision_optimizer- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2017-2795
An exploitable heap corruption vulnerability exists in the Txo functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/p... Read more
Affected Products : marklogic- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-2792
An exploitable heap corruption vulnerability exists in the iBldDirInfo functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can p... Read more
Affected Products : marklogic- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024