Latest CVE Feed
-
6.5
MEDIUMCVE-2017-11529
The ReadMATImage function in coders/mat.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory leak) via a crafted file.... Read more
Affected Products : imagemagick- EPSS Score: %0.54
- Published: Jul. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11590
There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.... Read more
Affected Products : libgxps- EPSS Score: %1.07
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11644
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the ReadMATImage() function in coders/mat.c.... Read more
Affected Products : imagemagick- EPSS Score: %0.38
- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11779
The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to proper... Read more
- EPSS Score: %38.26
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11782
The Microsoft Server Block Message (SMB) on Microsoft Windows 10 1607 and Windows Server 2016, allows an elevation of privilege vulnerability when an attacker sends specially crafted requests to the server, aka "Windows SMB Elevation of Privilege Vulnerab... Read more
- EPSS Score: %0.72
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11822
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the co... Read more
- EPSS Score: %20.53
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11806
ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". ... Read more
- EPSS Score: %24.37
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11820
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how Sha... Read more
Affected Products : sharepoint_enterprise_server- EPSS Score: %0.86
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11825
Microsoft Office 2016 Click-to-Run (C2R) and Microsoft Office 2016 for Mac allow an attacker to use a specially crafted file to perform actions in the security context of the current user, due to how Microsoft Office handles files in memory, aka "Microsof... Read more
- EPSS Score: %34.04
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11840
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, ... Read more
- EPSS Score: %76.21
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-11844
Microsoft Edge in Microsoft Windows 10 1703, 1709 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Discl... Read more
- EPSS Score: %11.39
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11845
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft Edge handles objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability".... Read more
- EPSS Score: %20.00
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-11848
Internet Explorer in Microsoft Microsoft Windows 7 SP1, Windows Server 2008 SP2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker t... Read more
- EPSS Score: %8.91
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11856
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to g... Read more
- EPSS Score: %19.30
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11918
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory ... Read more
- EPSS Score: %73.41
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15056
p_lx_elf.cpp in UPX 3.94 mishandles ELF headers, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by an Invalid Pointer Read in PackLinuxElf... Read more
- EPSS Score: %0.20
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-12154
The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omits the "use TPR shadow" vmcs12 control, which allows KVM... Read more
Affected Products : linux_kernel- EPSS Score: %0.03
- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
6.0
MEDIUMCVE-2017-12168
The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cycle Count Registe... Read more
Affected Products : linux_kernel- EPSS Score: %0.05
- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-12278
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Wireless LAN Controllers could allow an authenticated, remote attacker to cause an affected device to restart, resulting in a denial of service (DoS) condition. The vulner... Read more
Affected Products : wireless_lan_controller_software wireless_lan_controller wireless_lan_controller- EPSS Score: %0.81
- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-12329
A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of com... Read more
- EPSS Score: %0.38
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025