Latest CVE Feed
-
9.8
CRITICALCVE-2017-9225
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str() occurs during regular expression compilation. Code po... Read more
- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-9257
The mp4ff_read_ctts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.... Read more
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9243
Aries QWR-1104 Wireless-N Router with Firmware Version WRC.253.2.0913 has XSS on the Wireless Site Survey page, exploitable with the name of an access point.... Read more
- Published: May. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9251
andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the sitename parameter to admin.php.... Read more
Affected Products : finecms- Published: May. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9244
Cross-site scripting (XSS) vulnerability in the Trello app before 4.0.8 for iOS might allow remote attackers to inject arbitrary web script or HTML by uploading and attaching a crafted photo to a Card.... Read more
Affected Products : trello- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-9256
The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.... Read more
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-9255
The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.... Read more
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9360
WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.... Read more
Affected Products : websitebaker- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9262
In ImageMagick 7.0.5-6 Q16, the ReadJNGImage function in coders/png.c allows attackers to cause a denial of service (memory leak) via a crafted file.... Read more
Affected Products : imagemagick- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9304
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit function.... Read more
Affected Products : yara- Published: May. 31, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-9273
The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to unauthorized log configuration changes.... Read more
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9315
Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism is potentially at risk of being comp... Read more
- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9296
Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows remote attackers to redirect authenticated users to arbitrary web sites.... Read more
Affected Products : device_manager- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9294
RMI vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to execute internal commands without authentication via RMI ports.... Read more
Affected Products : device_manager- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9306
inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" substring.... Read more
Affected Products : syspass- Published: May. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9299
Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance because it represents a 2017 discovery of an issue in software ... Read more
Affected Products : otrs- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9354
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash. This was addressed in epan/dissectors/packet-rgmp.c by validating an IPv4 address.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-7977
The Screensavercc component in eLux RP before 5.5.0 allows attackers to bypass intended configuration restrictions and execute arbitrary commands with root privileges by inserting commands in a local configuration dialog in the control panel.... Read more
Affected Products : elux- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7927
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-... Read more
- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7980
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after ... Read more
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025