Latest CVE Feed
-
5.5
MEDIUMCVE-2017-18193
fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, which allows local users to cause a denial of service (BUG) via an application with multiple threads.... Read more
Affected Products : linux_kernel- Published: Feb. 22, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-18192
smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for Android allows attackers to access files via the backdoor 17621762 PIN.... Read more
Affected Products : photo\,video_locker-calculator- Published: Feb. 20, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-18191
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack ... Read more
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-18190
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.local... Read more
- Published: Feb. 16, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-18189
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18188
OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by creating a hard link inside a directory on which "chown -R" will be run.... Read more
Affected Products : opentmpfiles- Published: Feb. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18187
In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.... Read more
- Published: Feb. 14, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18186
An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.... Read more
Affected Products : qpdf- Published: Feb. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18185
An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.... Read more
Affected Products : qpdf- Published: Feb. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18184
An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.... Read more
Affected Products : qpdf- Published: Feb. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18183
An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.... Read more
Affected Products : qpdf- Published: Feb. 13, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-18179
Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted as a GET parameter. This is fixed in 10.1.... Read more
Affected Products : sitefinity- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-18178
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.... Read more
Affected Products : sitefinity- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18177
Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.... Read more
Affected Products : sitefinity- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18176
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is fixed in 10.1.... Read more
Affected Products : sitefinity- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-18175
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute of an IMG element. This is fixed in 10.1.... Read more
Affected Products : sitefinity- Published: Feb. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-18174
In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.... Read more
Affected Products : linux_kernel- Published: Feb. 11, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-18173
In case of using an invalid android verified boot signature with very large length, an integer underflow occurs in Snapdragon Mobile in SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 810, SD 820, SD 835, SDM630, SDM636, SDM660, Snapdragon_High_Med_201... Read more
Affected Products : sdm660_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_835_firmware sdm630_firmware sdm636_firmware snapdragon_high_med_2016_firmware sd_425_firmware sd_427_firmware +16 more products- Published: May. 06, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-18172
In a device, with screen size 1440x2560, the check of contiguous buffer will overflow on certain buffer size resulting in an Integer Overflow or Wraparound in System UI in Snapdragon Automobile, Snapdragon Mobile in version MDM9635M, SD 400, SD 410/12, SD... Read more
Affected Products : sdm660_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware mdm9635m_firmware sdm630_firmware sdm636_firmware sd_410_firmware +38 more products- Published: Oct. 23, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-18171
Improper input validation for GATT data packet received in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD ... Read more
Affected Products : android sdm660_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_835_firmware qca9379_firmware sdm710_firmware sdm630_firmware sdm636_firmware +41 more products- Published: Oct. 23, 2018
- Modified: Nov. 21, 2024