Latest CVE Feed
-
6.5
MEDIUMCVE-2017-15396
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a... Read more
- EPSS Score: %1.79
- Published: Aug. 28, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15395
A use after free in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka an ImageCapture NULL pointer dereference.... Read more
- EPSS Score: %1.50
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15394
Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permission dialogs via IDN homographs in a crafted Chrome Extension.... Read more
- EPSS Score: %1.31
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-15393
Insufficient Policy Enforcement in Devtools remote debugging in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to obtain access to remote debugging functionality via a crafted HTML page, aka a Referer leak.... Read more
- EPSS Score: %1.07
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-15392
Insufficient data validation in V8 in Google Chrome prior to 62.0.3202.62 allowed an attacker who can write to the Windows Registry to potentially exploit heap corruption via a crafted Windows Registry entry, related to PlatformIntegration.... Read more
- EPSS Score: %0.42
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15391
Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to access Extension pages without authorisation via a crafted HTML page.... Read more
- EPSS Score: %0.79
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15390
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.... Read more
- EPSS Score: %0.79
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15389
An insufficient watchdog timer in navigation in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.... Read more
- EPSS Score: %0.68
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-15388
Iteration through non-finite points in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.... Read more
- EPSS Score: %2.21
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-15387
Insufficient enforcement of Content Security Policy in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to open javascript: URL windows when they should not be allowed to via a crafted HTML page.... Read more
- EPSS Score: %1.07
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-15386
Incorrect implementation in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.... Read more
- EPSS Score: %0.79
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15367
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.... Read more
Affected Products : bacula-web- EPSS Score: %24.75
- Published: Mar. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-15365
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and rep... Read more
- EPSS Score: %0.40
- Published: Jan. 25, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2017-15358
Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors involving the --self-repair option.... Read more
Affected Products : charles- EPSS Score: %0.29
- Published: Aug. 03, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-15356
Huawei DP300, V500R002C00, RP200, V600R006C00, TE30, V100R001C10, V500R002C00,V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00,V600R006C00, TE60, V100R001C10, V500R002C00, V600R006C00, TX50,V500R002C00, V600R006C00 have a buffer overflow vul... Read more
Affected Products : dp300_firmware te60_firmware rp200_firmware te30_firmware te40_firmware te50_firmware tx50_firmware te30 te40 te50 +4 more products- EPSS Score: %0.27
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-15355
Huawei DP300, V500R002C00, RP200, V600R006C00, TE30, V100R001C10, V500R002C00,V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00,V600R006C00, TE60, V100R001C10, V500R002C00, V600R006C00, TX50,V500R002C00, V600R006C00 have a buffer overflow vul... Read more
Affected Products : dp300_firmware te60_firmware rp200_firmware te30_firmware te40_firmware te50_firmware tx50_firmware te30 te40 te50 +4 more products- EPSS Score: %0.27
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-15354
Huawei DP300, V500R002C00, RP200, V600R006C00, TE30, V100R001C10, V500R002C00,V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00,V600R006C00, TE60, V100R001C10, V500R002C00, V600R006C00, TX50,V500R002C00, V600R006C00 have a buffer overflow vul... Read more
Affected Products : dp300_firmware te60_firmware rp200_firmware te30_firmware te40_firmware te50_firmware tx50_firmware te30 te40 te50 +4 more products- EPSS Score: %0.27
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-15353
Huawei DP300, V500R002C00, RP200, V500R002C00, V600R006C00, RSE6500, V500R002C00, TE30, V100R001C02, V100R001C10, V500R002C00, V600R006C00, TE40, V500R002C00, V600R006C00, TE50, V500R002C00, V600R006C00, TE60, V100R001C01, V100R001C10, V500R002C00, V600R0... Read more
Affected Products : rse6500_firmware vp9660_firmware dp300_firmware te60_firmware viewpoint_9030_firmware rp200_firmware te30_firmware te40_firmware te50_firmware viewpoint_8660_firmware +12 more products- EPSS Score: %0.18
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
3.1
LOWCVE-2017-15352
Huawei OceanStor 2800 V3, V300R003C00, V300R003C20, OceanStor 5300 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5500 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5600 V3, V300R003C00, V300R003C10, V300R003C20, OceanStor 5800 V3, V300R003C0... Read more
- EPSS Score: %0.03
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2017-15351
The 'Find Phone' function in Huawei Honor V9 play smart phones with versions earlier than Jimmy-AL00AC00B135 has an authentication bypass vulnerability. Due to improper authentication realization in the 'Find Phone' function. An attacker may exploit the v... Read more
- EPSS Score: %0.02
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024