Latest CVE Feed
-
7.8
HIGHCVE-2017-11159
Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.d... Read more
- EPSS Score: %0.16
- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11092
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the KGSL driver function kgsl_ioctl_gpu_command, a Use After Free condition can potentially occur.... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11098
When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.... Read more
Affected Products : swftools- EPSS Score: %0.41
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11059
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different threads during SHA operations may potentially lead to a buffer overflow.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11029
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, camera application triggers "user-memory-access" issue as the Camera CPP module Linux driver directly accesses the application provided buffer,... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1101
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
Affected Products : rational_quality_manager- EPSS Score: %0.27
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1100
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
Affected Products : rational_quality_manager- EPSS Score: %0.27
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11002
In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.... Read more
Affected Products : android- EPSS Score: %0.10
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-10418
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: PeopleSoft CDA). The supported version that is affected is 8.56. Easily exploitable vulnerability allows low privileged attacker with network ... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.21
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10991
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.... Read more
- EPSS Score: %0.21
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10976
When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c.... Read more
Affected Products : swftools- EPSS Score: %0.33
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10901
Buffer overflow in PTW-WMS1 firmware version 2.000.012 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.... Read more
- EPSS Score: %0.70
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-10892
Untrusted search path vulnerability in Music Center for PC version 1.0.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
- EPSS Score: %0.11
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10888
BOOK WALKER for Windows Ver.1.2.9 and earlier, BOOK WALKER for Mac Ver.1.2.5 and earlier allow an attacker to access local files via unspecified vectors.... Read more
- EPSS Score: %0.20
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-10399
Vulnerability in the Oracle Hospitality Cruise Fleet Management component of Oracle Hospitality Applications (subcomponent: GangwayActivityWebApp). The supported version that is affected is 9.0.2.0. Difficult to exploit vulnerability allows low privileged... Read more
Affected Products : hospitality_cruise_fleet_management- EPSS Score: %0.30
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-10856
SEIL/X 4.60 to 5.72, SEIL/B1 4.60 to 5.72, SEIL/x86 3.20 to 5.72, SEIL/BPV4 5.00 to 5.72 allows remote attackers to cause a temporary failure of the device's encrypted communications via a specially crafted packet.... Read more
Affected Products : b1_firmware bpv_4_firmware x1_firmware x2_firmware x86_fuji_firmware b1 x1 x2 x86_fuji bpv_4- EPSS Score: %0.74
- Published: Sep. 15, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-10835
"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vectors.... Read more
- EPSS Score: %0.57
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10778
XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x00000000002... Read more
- EPSS Score: %0.05
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10773
XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at MSCTF!_CtfImeCreateT... Read more
- EPSS Score: %0.05
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9934
A PKCS#1 v1.5 signature verification routine in all Android releases from CAF using the Linux kernel may not check padding.... Read more
Affected Products : android- EPSS Score: %0.03
- Published: May. 16, 2017
- Modified: Apr. 20, 2025