Latest CVE Feed
-
9.8
CRITICALCVE-2017-8399
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."... Read more
Affected Products : pcre2- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8444
The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKeeper they could potentially obtain ... Read more
- Published: Sep. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8503
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to escape from the AppContainer sandbox, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8642.... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8386
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privile... Read more
- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8391
The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtain sensitive information by reading ... Read more
- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8451
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.... Read more
Affected Products : kibana- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8513
A remote code execution vulnerability exists in Microsoft PowerPoint when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability".... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8458
Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://[email protected]/ is displayed without a clear UI indication that it is not a resource on the safe.example.com web site.... Read more
Affected Products : brave- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2017-8470
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application ... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2017-8483
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via ... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8422
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.... Read more
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8440
Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.... Read more
Affected Products : kibana- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8420
SWFTools 2013-04-09-1007 on Windows has a "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x0000000000003e71" issue. This issue can be triggered by a malformed TTF file that is mishandled by font2swf. Attackers cou... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8449
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.... Read more
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8447
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a cluster, they may be able to issue both delete and index requests against that index.... Read more
- Published: Sep. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8448
An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch that results in that user gaining elevated privileges.... Read more
- Published: Sep. 29, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2017-8490
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via ... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8445
An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance that trusts all certificates. This could allow any node using any certificat... Read more
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-8518
Microsoft Edge allows a remote code execution vulnerability due to the way it accesses objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".... Read more
- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8536
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 17... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2016 exchange_server windows_defender security_essentials system_center_endpoint_protection +4 more products- Published: May. 26, 2017
- Modified: Apr. 20, 2025