Latest CVE Feed
-
7.8
HIGHCVE-2017-14961
In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300000c.... Read more
Affected Products : anti.virus- EPSS Score: %0.51
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-3794
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user. More Information: CSCuz03317. Known Affected Releases: 2.6. Known Fixed Re... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.22
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14908
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the SafeSwitch test application does not properly validate the number of blocks to verify.... Read more
Affected Products : android- EPSS Score: %0.11
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3757
An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on some Lenovo brand notebooks (not ThinkPads). This could allow an attacker with local privileges to execute code with administrative pr... Read more
Affected Products : elan_touchpad_driver- EPSS Score: %0.04
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3751
An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code with administrative privileges.... Read more
Affected Products : thinkpad_compact_usb_keyboard_driver- EPSS Score: %0.04
- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14895
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwpriv is not giving correct information.... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14524
Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2)... Read more
- EPSS Score: %5.99
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14834
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- EPSS Score: %0.37
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14757
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order fo... Read more
Affected Products : document_sciences_xpression- EPSS Score: %0.33
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-3477
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 12.0.0 and 12.1.0. Difficult to exploit vulnerability allows low privileged at... Read more
Affected Products : flexcube_private_banking- EPSS Score: %0.22
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3470
Vulnerability in the Oracle Communications Security Gateway component of Oracle Communications Applications (subcomponent: Network). The supported version that is affected is 3.0.0. Easily "exploitable" vulnerability allows unauthenticated attacker with n... Read more
Affected Products : communications_security_gateway- EPSS Score: %1.47
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14690
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at STDUJBIG2File!DllGetClassObject+0x00000000000064e7."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.06
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14681
The daemon in P3Scan 3.0_rc1 and earlier creates a p3scan.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for p3scan.pid modification before ... Read more
Affected Products : p3scan- EPSS Score: %0.05
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14641
A NULL pointer dereference was discovered in the AP4_DataAtom class in MetaData/Ap4MetaData.cpp in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.... Read more
Affected Products : bento4- EPSS Score: %0.56
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14627
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the... Read more
Affected Products : labelprint- EPSS Score: %50.20
- Published: Sep. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14588
Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.... Read more
- EPSS Score: %0.26
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14581
The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (service crash) via a crafted request, aka SAP Security Note 2389181.... Read more
Affected Products : netweaver_application_server_java- EPSS Score: %0.80
- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14539
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x000000000011d767.... Read more
Affected Products : irfanview- EPSS Score: %0.03
- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-14513
Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file via the f_filename parameter in a fingerprintdo action to admin/app/physical/physical.php.... Read more
Affected Products : metinfo- EPSS Score: %0.14
- Published: Sep. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1444
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus... Read more
Affected Products : emptoris_sourcing- EPSS Score: %0.20
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025