Latest CVE Feed
-
5.4
MEDIUMCVE-2017-15279
Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to Umbraco.Web.UI/umbraco/dialogs/P... Read more
Affected Products : umbraco_cms- EPSS Score: %0.20
- Published: Oct. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15262
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x000... Read more
- EPSS Score: %0.36
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15248
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlGetGlobalState+0x0000... Read more
- EPSS Score: %0.19
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15243
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Possible Stack Corruption starting at PDF!xmlGetGlobalState+0x000000... Read more
- EPSS Score: %0.10
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15215
Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated attacker to inject JavaScript via the searchtags parameter to index.php. If the victim is an administrator, an attacker can (for example) take over the admin session or change global ... Read more
Affected Products : shaarli- EPSS Score: %1.04
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15048
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.... Read more
Affected Products : zoom- EPSS Score: %21.43
- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14968
In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x830000c4, a related issue to CVE-2017-17113.... Read more
- EPSS Score: %0.05
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14961
In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300000c.... Read more
Affected Products : anti.virus- EPSS Score: %0.51
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-3794
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against an administrative user. More Information: CSCuz03317. Known Affected Releases: 2.6. Known Fixed Re... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.22
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14908
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the SafeSwitch test application does not properly validate the number of blocks to verify.... Read more
Affected Products : android- EPSS Score: %0.11
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3757
An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on some Lenovo brand notebooks (not ThinkPads). This could allow an attacker with local privileges to execute code with administrative pr... Read more
Affected Products : elan_touchpad_driver- EPSS Score: %0.04
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3751
An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code with administrative privileges.... Read more
Affected Products : thinkpad_compact_usb_keyboard_driver- EPSS Score: %0.04
- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14895
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwpriv is not giving correct information.... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14524
Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2)... Read more
- EPSS Score: %5.99
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14834
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- EPSS Score: %0.37
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14757
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order fo... Read more
Affected Products : document_sciences_xpression- EPSS Score: %0.33
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-3477
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 12.0.0 and 12.1.0. Difficult to exploit vulnerability allows low privileged at... Read more
Affected Products : flexcube_private_banking- EPSS Score: %0.22
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3470
Vulnerability in the Oracle Communications Security Gateway component of Oracle Communications Applications (subcomponent: Network). The supported version that is affected is 3.0.0. Easily "exploitable" vulnerability allows unauthenticated attacker with n... Read more
Affected Products : communications_security_gateway- EPSS Score: %1.47
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14690
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at STDUJBIG2File!DllGetClassObject+0x00000000000064e7."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.06
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14681
The daemon in P3Scan 3.0_rc1 and earlier creates a p3scan.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for p3scan.pid modification before ... Read more
Affected Products : p3scan- EPSS Score: %0.05
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025