Latest CVE Feed
-
6.5
MEDIUMCVE-2017-9937
In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.... Read more
Affected Products : libtiff- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9903
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx+0x00000000000117ff."... Read more
Affected Products : xnview- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9908
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at Xfpx+0x000000000000d6da."... Read more
Affected Products : xnview- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9927
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to a "Read Access Violation starting at image00000000_00400000+0x000000000001b5fe."... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9909
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!Rtl... Read more
Affected Products : xnview- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9988
The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c.... Read more
- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9916
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9991
Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (applicatio... Read more
Affected Products : ffmpeg- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9924
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV starting at image00000000_00400000+0x000000000001b72a."... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9921
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResGetMa... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9948
A stack buffer overflow vulnerability has been discovered in Microsoft Skype 7.2, 7.35, and 7.36 before 7.37, involving MSFTEDIT.DLL mishandling of remote RDP clipboard content within the message box.... Read more
Affected Products : skype- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9944
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to perform administrative operations ... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9955
The get_build_id function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted fil... Read more
Affected Products : binutils- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-9947
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/... Read more
Affected Products : apogee_pxc_firmware apogee_pxc_modular_firmware talon_tc_compact_firmware talon_tc_modular_firmware apogee_pxc_compact_\(p2_ethernet\)_firmware apogee_pxc_modular_\(bacnet\)_firmware apogee_pxc_modular_\(p2_ethernet\)_firmware talon_tc_compact_\(bacnet\)_firmware talon_tc_modular_\(bacnet\)_firmware apogee_pxc_modular +3 more products- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9961
A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code installation requires an access to the computer. By placing a specific DLL/OCX file, an attacker is able t... Read more
Affected Products : pro-face_gp_pro_ex- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9977
AVG AntiVirus for MacOS with scan engine before 4668 might allow remote attackers to bypass malware detection by leveraging failure to scan inside disk image (aka DMG) files.... Read more
- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9956
An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use that session ID as part of the HTTP cookie of a web reque... Read more
Affected Products : u.motion_builder- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9962
Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affecte... Read more
Affected Products : clearscada- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9957
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-pr... Read more
Affected Products : u.motion_builder- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9959
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users, supporting a denial of service condition.... Read more
Affected Products : u.motion_builder- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025