Latest CVE Feed
-
6.1
MEDIUMCVE-2017-16866
dayrui FineCms 5.2.0 before 2017.11.16 has Cross Site Scripting (XSS) in core/M_Controller.php via the DR_URI field.... Read more
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5622
With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the devic... Read more
- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5605
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.... Read more
Affected Products : movim- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5538
The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers to have unspecified impact via unknown vectors, which trigger an out-of-bound... Read more
Affected Products : samsung_mobile- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-5238
Due to a lack of bounds checking, several input configuration fields for the Eview EV-07S GPS Tracker will overflow data stored in one variable to another, overwriting the data of another field.... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16241
Incorrect access control in AMAG Symmetry Door Edge Network Controllers (EN-1DBC Boot App 23611 03.60 and STD App 23603 03.60; EN-2DBC Boot App 24451 01.00 and STD App 2461 01.00) enables remote attackers to execute door controller commands (e.g., lock, u... Read more
- Published: Dec. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-4994
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions prior to v4.3.0; and UAA bosh release ... Read more
Affected Products : cloud_foundry_uaa user_account_and_authentication cloud_foundry_uaa_bosh cloud_foundry_cf- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9964
In all Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in debug functionality.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15946
In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. The request method to execute is GET.... Read more
Affected Products : tag_meta- Published: Oct. 28, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9962
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15879
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export.... Read more
Affected Products : keystone- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15785
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation near NULL starting at Unknown Symbol @ 0x0000000000000000 called fro... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15766
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at Baba... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15761
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001ecaa."... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15757
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at Baba... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15755
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at veri... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15744
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Read Access Violation on Control Flow starting at CADIMAGE+0x00000000003d35a7."... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15743
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at ... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15741
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Possible Stack Corruption starting at CADIMAGE+0x00000000003d2378."... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15728
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords.... Read more
Affected Products : phpmyfaq- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025