Latest CVE Feed
-
7.8
HIGHCVE-2017-15566
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.... Read more
Affected Products : slurm- EPSS Score: %0.15
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15571
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.... Read more
- EPSS Score: %0.52
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15612
mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.... Read more
Affected Products : mistune- EPSS Score: %0.22
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-15896
Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way tha... Read more
Affected Products : node.js- EPSS Score: %0.10
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15908
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.... Read more
- EPSS Score: %0.35
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16360
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vul... Read more
- EPSS Score: %4.13
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16378
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is due to a computation that accesses ... Read more
- EPSS Score: %16.38
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16385
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an in... Read more
- EPSS Score: %27.43
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16395
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer access with an in... Read more
- EPSS Score: %26.27
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-16527
sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.... Read more
- EPSS Score: %0.12
- Published: Nov. 04, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-16532
The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.... Read more
- EPSS Score: %0.08
- Published: Nov. 04, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-16538
drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device, related to a missing... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Nov. 04, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16651
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to auth... Read more
- Actively Exploited
- EPSS Score: %30.53
- Published: Nov. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16671
A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus, it i... Read more
- EPSS Score: %3.64
- Published: Nov. 09, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-16672
An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip session object is created and that call gets rejected be... Read more
- EPSS Score: %5.27
- Published: Nov. 09, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-16786
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) the ntpclientcounterlogfile parameter to cgi-bin/mainv2 or (2) vectors involv... Read more
- EPSS Score: %0.30
- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16808
tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c.... Read more
Affected Products : tcpdump- EPSS Score: %1.16
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16837
Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users to overwrite dynamic PCRs of Trusted Platform Module (TPM) by hooking these function pointers.... Read more
Affected Products : trusted_boot- EPSS Score: %0.12
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16879
Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.... Read more
Affected Products : ncurses- EPSS Score: %0.44
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17028
A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.... Read more
Affected Products : qts- EPSS Score: %3.24
- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025