Latest CVE Feed
-
7.8
HIGHCVE-2017-15765
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address is used as one or more arguments in a subs... Read more
- EPSS Score: %0.19
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15763
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Imag... Read more
- EPSS Score: %0.36
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15754
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x00000000... Read more
- EPSS Score: %0.19
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15751
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at BabaCAD4Image!ShowPlugInOptions+0... Read more
- EPSS Score: %0.10
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15734
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.13
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15729
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.13
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-6144
In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the server's certificate is not verified. Attackers in a privileged network position may be able to launch a man-in-the-middle attack against t... Read more
Affected Products : big-ip_policy_enforcement_manager- EPSS Score: %0.17
- Published: Oct. 20, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-14937
The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to the internal CAN bus (or the OBD connector). This affects the airbag control units (aka pyrotechnical control units or PCUs) of unspecifi... Read more
Affected Products : pcu- EPSS Score: %5.75
- Published: Oct. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10933
All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by directory traversal vulnerability that allows remote attackers to read arbitrary files on the system via a full path name after host address.... Read more
- EPSS Score: %0.41
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-10403
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: iQuery). Supported versions that are affected are 8.5.1 and 9.0.0. Difficult to exploit vulnerability allows low privileged attacke... Read more
Affected Products : hospitality_reporting_and_analytics- EPSS Score: %0.92
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
8.7
HIGHCVE-2017-10401
Vulnerability in the Oracle Hospitality Cruise Materials Management component of Oracle Hospitality Applications (subcomponent: MMSUpdater). The supported version that is affected is 7.30.564.0. Easily exploitable vulnerability allows low privileged attac... Read more
Affected Products : hospitality_cruise_materials_management- EPSS Score: %0.04
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10397
Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: BaseMasterPage). The supported version that is affected is 9.0.2.0. Easily exploitable vulnerability allows unauthenticated attacke... Read more
Affected Products : hospitality_cruise_fleet_management- EPSS Score: %0.49
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2017-10396
Vulnerability in the Oracle Hospitality Cruise AffairWhere component of Oracle Hospitality Applications (subcomponent: AffairWhere). Supported versions that are affected are 2.2.5.0, 2.2.6.0 and 2.2.7.0. Easily exploitable vulnerability allows low privile... Read more
Affected Products : hospitality_cruise_affairwhere- EPSS Score: %0.44
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10394
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Security). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with net... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.33
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-10386
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Easily exploitable vulnerability allows high privileged attacker wit... Read more
- EPSS Score: %0.31
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10381
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attac... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.47
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-10380
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Difficult to exploit vulnerability allows unauthenticated attacker w... Read more
- EPSS Score: %0.54
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-10362
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Sawbridge). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with n... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.57
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-10359
Vulnerability in the Oracle Hyperion BI+ component of Oracle Hyperion (subcomponent: UI and Visualization). The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP t... Read more
- EPSS Score: %0.46
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-10353
Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network a... Read more
Affected Products : hospitality_hotel_mobile- EPSS Score: %0.76
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025