Latest CVE Feed
-
6.1
MEDIUMCVE-2017-8791
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos/courier/login.html auth_params CRLF attack vector.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.9
MEDIUMCVE-2017-8831
The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact by changing a certain sequenc... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8803
Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a "Data from Faulting Address controls Code Flow" issue. One threat model is a victim who obtains an untrusted crafte... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8818
curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact because too little memory is allocated for interfacing to an SSL library... Read more
- Published: Nov. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8810
MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate ac... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8845
The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8814
The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-8822
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of ... Read more
- Published: Dec. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8816
The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vecto... Read more
- Published: Nov. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUM- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8801
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.... Read more
Affected Products : officescan- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8875
CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.... Read more
Affected Products : clean_login- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8826
FastStone Image Viewer 6.2 has a "User Mode Write AV" issue, possibly related to the jpeg_mem_term function in jmemnobs.c in libjpeg. This issue can be triggered by a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this iss... Read more
Affected Products : image_viewer- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8829
Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with a crafted YAML file.... Read more
Affected Products : lintian- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8835
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeratio... Read more
Affected Products : b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware balance_305 balance_380 balance_580 balance_710 +2 more products- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8898
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/... Read more
Affected Products : invision_power_board- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8839
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/preview.cgi.... Read more
Affected Products : b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware balance_305 balance_380 balance_580 balance_710 +2 more products- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8904
Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.... Read more
Affected Products : xen- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8837
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of thes... Read more
Affected Products : b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware balance_305 balance_380 balance_580 balance_710 +2 more products- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8896
ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters.... Read more
Affected Products : owncloud- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025