Latest CVE Feed
-
10.0
HIGHCVE-2017-17773
In Snapdragon Automobile, Snapdragon Wearable and Snapdragon Mobile MDM9206,MDM9607,MDM9650,SD 210/SD 212/SD 205,SD 400,SD 410/12,SD 425,SD 430,SD 450,SD 600,SD 602A,SD 615/16/SD 415,SD 617,SD 625,SD 650/52,SD 800,SD 808,SD 810,SD 820,SD 820Am,SD 835,SD 8... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_835_firmware mdm9650_firmware msm8909w_firmware mdm9206_firmware mdm9607_firmware sd_410_firmware sd_412_firmware +48 more products- Published: Mar. 15, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-17771
In msm_isp_prepare_v4l2_buf in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-02-12, an array out of bounds can occur.... Read more
Affected Products : android- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-17770
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in a power driver ioctl handler, an Untrusted Pointer Dereference may potentially occur.... Read more
Affected Products : android- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-17769
Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.... Read more
Affected Products : android- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-17767
In all Qualcomm products with Android releases from CAF using the Linux kernel, the IL client may free a buffer OMX Video Encoder Component and then subsequently access the already freed buffer.... Read more
Affected Products : android- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17766
In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received from firmware is not properly validated so that an integer overflow vulnerability in the size of a buffer allocatio... Read more
Affected Products : android- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-17765
In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in wma_get_ll_stats_ext_buf() and are used to allocate the sizes of buffers and may be vulnerable to integer ... Read more
Affected Products : android- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-17764
In all Qualcomm products with Android releases from CAF using the Linux kernel, the num_failure_info value from firmware is not properly validated in wma_rx_aggr_failure_event_handler() so that an integer overflow vulnerability in a buffer size calculatio... Read more
Affected Products : android- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-17762
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.... Read more
Affected Products : episerver- Published: Aug. 29, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-17751
Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket Protocol.... Read more
Affected Products : soundtouch- Published: Mar. 24, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-17750
Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify.... Read more
Affected Products : soundtouch- Published: Mar. 24, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-17749
Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.... Read more
Affected Products : soundtouch- Published: Mar. 24, 2018
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2017-17743
Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.20, 5.0.x before 5.0.19, and 5.1.x before 5.1.11 allows authenticated remote attackers to escape the shell and escalate their privileges... Read more
- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-17742
Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 allows an HTTP Response Splitting attack. An attacker can inject a crafted key and value into an HTTP response for the HTTP server of WEBrick.... Read more
- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17736
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.... Read more
- Published: Mar. 23, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-17725
In Exiv2 0.26, there is an integer overflow leading to a heap-based buffer over-read in the Exiv2::getULong function in types.cpp. Remote attackers can exploit the vulnerability to cause a denial of service via a crafted image file. Note that this vulnera... Read more
Affected Products : exiv2- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-17724
In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::IptcData::printStructure function in iptc.cpp, related to the "!= 0x1c" case. Remote attackers can exploit this vulnerability to cause a denial of service via a crafted TIFF file.... Read more
Affected Products : exiv2- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2017-17723
In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnerability to disclose memory data or cause a denial of service via a crafted TIFF file.... Read more
Affected Products : exiv2- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-17722
In Exiv2 0.26, there is a reachable assertion in the readHeader function in bigtiffimage.cpp, which will lead to a remote denial of service attack via a crafted TIFF file.... Read more
Affected Products : exiv2- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-17708
Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other users in Pleasant Password Server before 7.8.3.... Read more
Affected Products : pleasant_password_server- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024