Latest CVE Feed
-
5.4
MEDIUMCVE-2017-8302
Mura CMS 7.0.6967 allows admin/?muraAction= XSS attacks, related to admin/core/views/carch/list.cfm, admin/core/views/carch/loadsiteflat.cfm, admin/core/views/cusers/inc/dsp_nextn.cfm, admin/core/views/cusers/inc/dsp_search_form.cfm, admin/core/views/cuse... Read more
Affected Products : muracms- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-8280
In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan calibration data store and retrieve operation, there are some potential race conditions which lead to a memory leak and a buffer overflow during the context sw... Read more
Affected Products : android- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8303
An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8369
IrfanView version 4.44 (32bit) has a "Data from Faulting Address controls Branch Selection starting at USER32!wvsprintfA+0x00000000000002f3" issue, which might allow attackers to execute arbitrary code via a crafted file.... Read more
Affected Products : irfanview- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8402
PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file.... Read more
Affected Products : pivotx- Published: May. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8308
In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of the Avast product. This bypasses the Self-Defense feature of the product, opening a door to subsequent attac... Read more
Affected Products : antivirus- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-8418
RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.... Read more
Affected Products : rubocop- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-8327
The bmpr_read_uncompressed function in imagew-bmp.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted image.... Read more
- Published: Apr. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8338
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all de... Read more
Affected Products : routeros- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8310
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles fil... Read more
Affected Products : vlc_media_player- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8362
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.... Read more
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-8342
Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.... Read more
Affected Products : radicale- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8394
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 4 due to NULL pointer dereferencing of _bfd_elf_large_com_section. This vulnerability causes programs that conduct an anal... Read more
Affected Products : binutils- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8349
In ImageMagick 7.0.5-5, the ReadSFWImage function in sfw.c allows attackers to cause a denial of service (memory leak) via a crafted file.... Read more
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
4.5
MEDIUMCVE-2017-8382
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts.... Read more
Affected Products : admidio- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8351
In ImageMagick 7.0.5-5, the ReadPCDImage function in pcd.c allows attackers to cause a denial of service (memory leak) via a crafted file.... Read more
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8396
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing reloc offset range tests didn't catch small negative offsets less than the size of the reloc field.... Read more
Affected Products : binutils- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2017-8472
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosur... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8358
LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/source/filter/jpeg/jpegc.cxx.... Read more
Affected Products : libreoffice- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8361
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.... Read more
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025