Latest CVE Feed
-
5.4
MEDIUMCVE-2017-14379
EMC RSA Authentication Manager before 8.2 SP1 P6 has a cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.... Read more
Affected Products : rsa_authentication_manager- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-1452
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.... Read more
- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-14595
In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.... Read more
Affected Products : joomla\!- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-14602
A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 b... Read more
- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14683
geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.... Read more
Affected Products : geminabox- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14741
The ReadCAPTIONImage function in coders/caption.c in ImageMagick 7.0.7-3 allows remote attackers to cause a denial of service (infinite loop) via a crafted font file.... Read more
Affected Products : imagemagick- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14746
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.... Read more
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14767
The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allows remote attackers to cause a denial of service (heap buffer overflow) or possibly have unspecified other ... Read more
Affected Products : ffmpeg- Published: Sep. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14862
An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.... Read more
- Published: Sep. 29, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-14970
In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller,... Read more
Affected Products : openvswitch- Published: Oct. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14994
ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonNativeImages to yield an image list with zero frames.... Read more
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15015
ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in PDFDelegateMessage in coders/pdf.c.... Read more
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15018
LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_4 in vbrquantize.c.... Read more
Affected Products : lame- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15046
LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vulnerability than CVE-2017-9412.... Read more
Affected Products : lame- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-15086
It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.... Read more
- Published: Nov. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15115
The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly h... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15566
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.... Read more
Affected Products : slurm- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15571
In Redmine before 3.2.8, 3.3.x before 3.3.5, and 3.4.x before 3.4.3, XSS exists in app/views/issues/_list.html.erb via crafted column data.... Read more
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15612
mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.... Read more
Affected Products : mistune- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-15896
Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way tha... Read more
Affected Products : node.js- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025