Latest CVE Feed
-
4.8
MEDIUMCVE-2017-9452
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : piwigo- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9444
BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versions= ... Read more
Affected Products : bigtree_cms- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9445
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved in... Read more
Affected Products : systemd- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9467
Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via un... Read more
Affected Products : pan-os- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9499
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attackers to cause a denial of service via a crafted file.... Read more
Affected Products : imagemagick- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9586
The "FSBY Mobile Banking" by First State Bank of Yoakum TX app 3.0.0 -- aka fsby-mobile-banking/id899136434 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive informa... Read more
Affected Products : fsby_mobile_banking- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9459
Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecifie... Read more
Affected Products : pan-os- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9470
In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.... Read more
Affected Products : ytnef- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-9462
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.... Read more
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-9491
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco D... Read more
Affected Products : arris_tg1682g_firmware dpc3939_firmware dpc3941t_firmware dpc3939b_firmware dpc3939 arris_tg1682g dpc3941t dpc3939b- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9500
In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attackers to cause a denial of service via a crafted file.... Read more
Affected Products : imagemagick- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9473
In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.... Read more
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9529
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx+0x0000000000004efd."... Read more
Affected Products : xnview- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9545
The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote attackers to cause a denial of service (buffer over-read) via a crafted mp3 file.... Read more
Affected Products : mpg123- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9485
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to write arbitrary data to a known /var/tmp/sess_* pathname by leveraging the device's operation in UI dev mode.... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9503
QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command... Read more
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9486
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to compute password-of-the-day values via unspecified vectors.... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9536
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x00000... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9487
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD_sey) devices allows remote attackers to discover a WAN IPv6 IP address by leveraging knowledge of the CM ... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9533
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!DE_Decode+0x0000000000000a9b."... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025