Latest CVE Feed
-
7.8
HIGHCVE-2017-9687
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, two concurrent threads/processes can write the value of "0" to the debugfs file that controls ipa ipc log which will lead to the double-free in... Read more
Affected Products : android- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9659
A Stack-Based Buffer Overflow issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. The stack-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.... Read more
Affected Products : monitouch_v-sft- Published: Aug. 14, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9507
The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.... Read more
- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9489
The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF.... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-9366
Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Base/Dashboard/Dashboard_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted tab_name parameter.... Read more
Affected Products : epesi- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9303
Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.... Read more
- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1000170
jqueryFileTree 2.1.5 and older Directory Traversal... Read more
Affected Products : jqueryfiletree- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9252
andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the search page via the text-search parameter to index.php in a route=search action.... Read more
Affected Products : finecms- Published: May. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9231
XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.... Read more
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14260
In the SDK in Bento4 1.5.0-616, the AP4_StssAtom class in Ap4StssAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.... Read more
Affected Products : bento4- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14259
In the SDK in Bento4 1.5.0-616, the AP4_StscAtom class in Ap4StscAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.... Read more
Affected Products : bento4- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14257
In the SDK in Bento4 1.5.0-616, AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a crafted .MP4 file.... Read more
Affected Products : bento4- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8935
The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : indiana_voters- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8891
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.... Read more
Affected Products : lepton- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8658
A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".... Read more
Affected Products : chakracore- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6760
An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to ... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8368
Sublime Text 3 Build 3126 allows user-assisted attackers to cause a denial of service or possibly have unspecified other impact via a crafted .mkv file. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues s... Read more
Affected Products : sublime_text_3- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2844
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attac... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8131
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privi... Read more
Affected Products : fusionsphere_openstack- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2014-3926
Cross-site scripting (XSS) vulnerability in lg.cgi in Cougar LG 1.9 allows remote attackers to inject arbitrary web script or HTML via the "addr" parameter.... Read more
Affected Products : lg- Published: Mar. 13, 2017
- Modified: Apr. 20, 2025