Latest CVE Feed
-
8.8
HIGHCVE-2017-8928
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.... Read more
Affected Products : mailcow\- Published: May. 14, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8936
The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ... Read more
Affected Products : dolphin_web_browser- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8940
The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : healthy_recipes_and_grocery_deals- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9042
readelf.c in GNU Binutils 2017-04-12 has a "cannot be represented in type long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file.... Read more
Affected Products : binutils- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9041
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to MIPS GOT mishandling in the process_mips_specific function in readelf.c.... Read more
Affected Products : binutils- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9070
In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9036
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.... Read more
Affected Products : serverprotect- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9064
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9076
The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue ... Read more
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9048
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end of the... Read more
Affected Products : libxml2- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9034
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failure to validate software updates.... Read more
Affected Products : serverprotect- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9045
The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.... Read more
Affected Products : google_i\/o_2017- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9023
The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.... Read more
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9040
GNU Binutils 2017-04-03 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash), related to the process_mips_specific function in readelf.c, via a crafted ELF file that triggers a large memory-allocation attem... Read more
Affected Products : binutils- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9098
ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-run... Read more
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9026
Stack buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote unauthenticated attackers to control the program counter via a specially crafted fname parameter of a GET request.... Read more
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9038
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the byte_get_little_endian function in elfcomm.c, the get_unwind_section_word function in readelf... Read more
Affected Products : binutils- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9110
In OpenEXR 2.2.0, an invalid read of size 2 in the hufDecode function in ImfHuf.cpp could cause the application to crash.... Read more
Affected Products : openexr- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9051
libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c.... Read more
Affected Products : libav- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9055
An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were not checked for being in bounds, leading to a heap-based buffer over-read.... Read more
Affected Products : libdwarf- Published: May. 18, 2017
- Modified: Apr. 20, 2025