Latest CVE Feed
-
9.8
CRITICALCVE-2017-8923
The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects that result in a negative length, which allows remote attackers to cause a denial of service (application crash) or possibly have unspeci... Read more
Affected Products : php- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8860
Information disclosure through directory listing on the Cohu 3960HD allows an attacker to view and download source code, log files, and other sensitive device information via a specially crafted web request with an extra / character, such as a "GET // HTT... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-8872
The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.... Read more
Affected Products : libxml2- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8878
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8941
The Interval International app 3.3 through 3.5.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : interval_international- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8918
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.... Read more
Affected Products : dive_assistant- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8930
Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of admins for requests that can (1) create new administrator user accounts and take over the entire application... Read more
Affected Products : simple_invoices- Published: May. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9044
The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted ELF file.... Read more
Affected Products : binutils- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8917
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : joomla\!- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8938
The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : radio_javan- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8920
irc.cgi in CGI:IRC before 0.5.12 reflects user-supplied input from the R parameter without proper output encoding, aka XSS.... Read more
Affected Products : cgi\- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8925
The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.... Read more
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8928
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.... Read more
Affected Products : mailcow\- Published: May. 14, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8936
The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted ... Read more
Affected Products : dolphin_web_browser- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8940
The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : healthy_recipes_and_grocery_deals- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9042
readelf.c in GNU Binutils 2017-04-12 has a "cannot be represented in type long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file.... Read more
Affected Products : binutils- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9041
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to MIPS GOT mishandling in the process_mips_specific function in readelf.c.... Read more
Affected Products : binutils- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9070
In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9036
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.... Read more
Affected Products : serverprotect- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9064
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025