Latest CVE Feed
-
8.8
HIGHCVE-2017-10678
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.... Read more
Affected Products : piwigo- EPSS Score: %0.18
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10752
XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpL... Read more
- EPSS Score: %0.05
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10748
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000022bf8d."... Read more
- EPSS Score: %0.06
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10728
Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."... Read more
Affected Products : winamp- EPSS Score: %0.36
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10687
In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.... Read more
Affected Products : libsass- EPSS Score: %0.42
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-10680
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.... Read more
Affected Products : piwigo- EPSS Score: %0.18
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10674
Antiy Antivirus Engine 5.0.0.06281654 allows local users to cause a denial of service (BSOD) via a long third argument in a DeviceIoControl call.... Read more
Affected Products : antivirus_engine- EPSS Score: %0.04
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
4.4
MEDIUMCVE-2017-10606
Version 4.40 of the TPM (Trusted Platform Module) firmware on Juniper Networks SRX300 Series has a weakness in generating cryptographic keys that may allow an attacker to decrypt sensitive information in SRX300 Series products. The TPM is used in the SRX3... Read more
- EPSS Score: %0.05
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-9977
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in PlayReady DRM.... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-10423
Vulnerability in the Oracle Retail Back Office component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 13.2, 13.3, 13.4, 14.0 and 14.1. Easily exploitable vulnerability allows low privileged attacker with... Read more
Affected Products : retail_back_office- EPSS Score: %0.22
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-9979
In all Qualcomm products with Android releases from CAF using the Linux kernel, a variable is uninitialized in a TrustZone system call potentially leading to the compromise of secure memory.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-9978
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE service.... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-9973
In all Qualcomm products with Android releases from CAF using the Linux kernel, validation of a buffer length was missing in a PlayReady DRM routine.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-9968
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in the UIMDIAG interface.... Read more
Affected Products : android- EPSS Score: %0.19
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9947
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9944
In the Secure File System in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9928
In GERAN in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9933
Due to missing input validation in all Android releases from CAF using the Linux kernel, HLOS can write to fuses for which it should not have access.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9927
In UIM in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
6.9
MEDIUMCVE-2017-10370
Vulnerability in the Oracle Hospitality Guest Access component of Oracle Hospitality Applications (subcomponent: Base). Supported versions that are affected are 4.2.0 and 4.2.1. Easily exploitable vulnerability allows high privileged attacker with network... Read more
Affected Products : hospitality_guest_access- EPSS Score: %0.31
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025