Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2017-14448

    An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trig... Read more

    Affected Products : debian_linux sdl_image
    • Published: Apr. 24, 2018
    • Modified: Nov. 21, 2024
  • 8.5

    HIGH
    CVE-2017-14447

    An exploitable buffer overflow vulnerability exists in the PubNub message handler for the 'ad' channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwri... Read more

    Affected Products : hub_firmware hub
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2017-14446

    An exploitable stack-based buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation unsafely extracts parameters from the query string, leading to a buffer overflow on the stack. An attacker can sen... Read more

    Affected Products : hub_firmware hub
    • Published: Aug. 02, 2018
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2017-14445

    An exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly handles the host parameter during a firmware update request, leading to a buffer overflow on a global section. An ... Read more

    Affected Products : hub_firmware hub
    • Published: Aug. 02, 2018
    • Modified: Nov. 21, 2024
  • 9.9

    CRITICAL
    CVE-2017-14444

    An exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly handles the URL parameter during a firmware update request, leading to a buffer overflow on a global section. An a... Read more

    Affected Products : hub_firmware hub
    • Published: Aug. 02, 2018
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2017-14443

    An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily controlled information leak on the whole ... Read more

    Affected Products : hub_2245-222_firmware hub_2245-222
    • Published: Sep. 17, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2017-14442

    An exploitable code execution vulnerability exists in the BMP image rendering functionality of SDL2_image-2.0.2. A specially crafted BMP image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to tri... Read more

    Affected Products : debian_linux sdl_image
    • Published: Apr. 24, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2017-14441

    An exploitable code execution vulnerability exists in the ICO image rendering functionality of SDL2_image-2.0.2. A specially crafted ICO image can cause an integer overflow, cascading to a heap overflow resulting in code execution. An attacker can display... Read more

    Affected Products : debian_linux sdl_image
    • Published: Apr. 24, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2017-14440

    An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can cause a stack overflow resulting in code execution. An attacker can display a specially crafted image to t... Read more

    Affected Products : debian_linux sdl_image
    • Published: Apr. 24, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-14439

    Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4001/tcp to trigger this vulnerab... Read more

    Affected Products : edr-810_firmware edr-810
    • Published: May. 14, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-14438

    Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4000/tcp to trigger this vulnerab... Read more

    Affected Products : edr-810_firmware edr-810
    • Published: May. 14, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-14437

    An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request... Read more

    Affected Products : edr-810_firmware edr-810
    • Published: May. 14, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-14436

    An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request... Read more

    Affected Products : edr-810_firmware edr-810
    • Published: May. 14, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-14435

    An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request... Read more

    Affected Products : edr-810_firmware edr-810
    • Published: May. 14, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2017-14434

    An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the ... Read more

    Affected Products : edr-810_firmware edr-810
    • Published: May. 14, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2017-14433

    An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the ... Read more

    Affected Products : edr-810_firmware edr-810
    • Published: May. 14, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2017-14432

    An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the ... Read more

    Affected Products : edr-810_firmware edr-810
    • Published: May. 14, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-14395

    Auth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to execute a script in the user's browser... Read more

    Affected Products : access_management openam
    • Published: Jun. 19, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-14394

    OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated r... Read more

    Affected Products : access_management openam
    • Published: Jun. 19, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2017-14384

    In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversal vulnerability. A remote malicious user could potentially exploit this vulnerability to read unauthorized files by supplying specially... Read more

    Affected Products : storage_manager
    • Published: Mar. 16, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 293331 Results