Latest CVE Feed
-
5.5
MEDIUMCVE-2017-0911
Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login with Twitter" authentication information is pa... Read more
Affected Products : twitter_kit- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-0869
NVIDIA driver contains an integer overflow vulnerability which could cause a use after free and possibly lead to an elevation of privilege enabling code execution as a privileged process. This issue is rated as high. Version: N/A. Android ID: A-37776156. ... Read more
Affected Products : android- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-0855
In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks. This could lead to remote denial of service of a critical system process with no additional execution privi... Read more
Affected Products : android- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-0846
An information disclosure vulnerability in the Android framework (clipboardservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64934810.... Read more
Affected Products : android- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-0751
An elevation of privilege vulnerability in the Qualcomm QCE driver. Product: Android. Versions: Android kernel. Android ID: A-36591162. References: QC-CR#2045061.... Read more
Affected Products : android- Published: Apr. 05, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-0748
An information disclosure vulnerability in the Qualcomm audio driver. Product: Android. Versions: Android Kernel. Android ID: A-35764875. References: QC-CR#2029798.... Read more
Affected Products : android- Published: Apr. 05, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-0744
An elevation of privilege vulnerability in the NVIDIA firmware processing code. Product: Android. Versions: Android kernel. Android ID: A-34112726. References: N-CVE-2017-0744.... Read more
Affected Products : android- Published: Apr. 05, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-0431
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-32573899.... Read more
Affected Products : android- Published: Apr. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-0372
Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-0371
MediaWiki before 1.23.16, 1.24.x through 1.27.x before 1.27.2, and 1.28.x before 1.28.1 allows remote attackers to discover the IP addresses of Wiki visitors via a style="background-image: attr(title url);" attack within a DIV element that has an attacker... Read more
Affected Products : mediawiki- Published: Feb. 18, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-0370
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-0369
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-0368
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-0367
Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-0366
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw allowing to evade SVG filter using default attribute values in DTD declaration.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2017-0365
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a XSS vulnerability in SearchHighlighter::highlightText() with non-default configurations.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-0364
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-0363
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-0362
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-0361
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains an information disclosure flaw, where the api.log might contain passwords in plaintext.... Read more
- Published: Apr. 13, 2018
- Modified: Nov. 21, 2024