Latest CVE Feed
-
7.1
HIGHCVE-2017-9256
The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.... Read more
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-9255
The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.... Read more
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9360
WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.... Read more
Affected Products : websitebaker- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9262
In ImageMagick 7.0.5-6 Q16, the ReadJNGImage function in coders/png.c allows attackers to cause a denial of service (memory leak) via a crafted file.... Read more
Affected Products : imagemagick- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9304
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit function.... Read more
Affected Products : yara- Published: May. 31, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-9273
The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to unauthorized log configuration changes.... Read more
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9315
Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism is potentially at risk of being comp... Read more
- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9296
Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows remote attackers to redirect authenticated users to arbitrary web sites.... Read more
Affected Products : device_manager- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9294
RMI vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to execute internal commands without authentication via RMI ports.... Read more
Affected Products : device_manager- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9306
inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" substring.... Read more
Affected Products : syspass- Published: May. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9299
Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance because it represents a 2017 discovery of an issue in software ... Read more
Affected Products : otrs- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9354
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash. This was addressed in epan/dissectors/packet-rgmp.c by validating an IPv4 address.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-7977
The Screensavercc component in eLux RP before 5.5.0 allows attackers to bypass intended configuration restrictions and execute arbitrary commands with root privileges by inserting commands in a local configuration dialog in the control panel.... Read more
Affected Products : elux- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7927
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-... Read more
- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7980
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after ... Read more
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-7934
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older protocol versions contains a flaw that could allow a malicious user to authenticate with a server and then cau... Read more
Affected Products : pi_data_archive- Published: Aug. 25, 2017
- Modified: Apr. 20, 2025
-
6.0
MEDIUMCVE-2017-7932
An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX ... Read more
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8020
An issue was discovered in EMC ScaleIO 2.0.1.x. A buffer overflow vulnerability in the SDBG service may potentially allow a remote unauthenticated attacker to execute arbitrary commands with root privileges on an affected server.... Read more
Affected Products : scaleio- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8040
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard. Privileged users can in some cases upload malfor... Read more
Affected Products : single_sign-on_for_pivotal_cloud_foundry- Published: Sep. 09, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8055
WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and invalid usernames.... Read more
Affected Products : fireware- Published: Apr. 22, 2017
- Modified: Apr. 20, 2025