Latest CVE Feed
-
5.9
MEDIUMCVE-2017-2585
Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.... Read more
- Published: Mar. 12, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-2582
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the ... Read more
- Published: Jul. 26, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-2581
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.... Read more
Affected Products : netpbm- Published: Jul. 27, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-2580
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.... Read more
Affected Products : netpbm- Published: Jul. 27, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-2579
An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file could cause the application to crash or possibly allows code execution.... Read more
Affected Products : netpbm- Published: Jul. 27, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-2575
A vulnerability was found while fuzzing libbpg 0.9.7. It is a NULL pointer dereference issue due to missing check of the return value of function malloc in the BPG encoder. This vulnerability appeared while converting a malicious JPEG file to BPG.... Read more
Affected Products : libbpg- Published: Aug. 22, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-2493
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers t... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-2492
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "JavaScriptCore" component. It allows remote attackers to conduct Universal XSS (UXSS) att... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-2488
A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol. This issue is fixed in Apple Remote Desktop 3.9. An attacker may be able to cap... Read more
Affected Products : remote_desktop- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2017-2411
In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.... Read more
Affected Products : iphone_os- Published: Jan. 11, 2019
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2017-2375
An issue existed in preventing the uploading of CallKit call history to iCloud. This issue was addressed through improved logic. This issue is fixed in iOS 10.2.1. Updates for CallKit call history are sent to iCloud.... Read more
Affected Products : iphone_os- Published: Dec. 23, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-2297
Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled RBAC access tokens. This issue has been fixed in Puppet Enterprise 2016.4.5 and 2017.2.1. This only affects users with labeled tokens, ... Read more
Affected Products : puppet_enterprise- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-2296
In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Classifier node group names or RBAC role display names causes errors, effectively causing a DOS to the service. This was resolved in Puppet... Read more
Affected Products : puppet_enterprise- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-2293
Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that allowed the package plugin to install or remove arbitrary packages on all managed agents. This release adds default configuration to not allow these... Read more
Affected Products : puppet_enterprise- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-2166
Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.... Read more
Affected Products : groupsession- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2158
Improper verification when expanding ZIP64 archives in Lhaplus versions 1.73 and earlier may lead to unintended contents to be extracted from a specially crafted ZIP64 archive.... Read more
Affected Products : lhaplus- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2017-20191
A vulnerability was found in Zimbra zm-admin-ajax up to 8.8.1. It has been classified as problematic. This affects the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js of the component Form Textbox Field Error Hand... Read more
Affected Products :- Published: Mar. 31, 2024
- Modified: Nov. 21, 2024
-
0.0
NACVE-2017-20190
Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a "Zalgo text" attack. NOTE: third parties dispute whether the computational ... Read more
- Published: Mar. 27, 2024
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2017-20188
A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerability is the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js. The manipulation of the argument m... Read more
Affected Products : zm-ajax- Published: Jan. 02, 2024
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-20187
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The manipulation of the argument email/na... Read more
Affected Products : magnesium-php- Published: Nov. 05, 2023
- Modified: Nov. 21, 2024