Latest CVE Feed
-
6.1
MEDIUMCVE-2017-7723
XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.... Read more
Affected Products : easy_wp_smtp- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7862
FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c.... Read more
Affected Products : ffmpeg- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7717
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2356504.... Read more
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7718
hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirr... Read more
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7725
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "canonical" URL on installation of concrete5 using the "Advanced Options" settings. Remote attackers can make a GET request with any domai... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7728
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.... Read more
- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7747
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting additions to the protocol tree.... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7745
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-sigcomp.c by correcting a memory-size check.... Read more
Affected Products : wireshark- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7748
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check.... Read more
Affected Products : wireshark- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-7885
Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from process memory, because of an integer overflow in the jbig2_decode_symbol_dict function in jbig2_symbol_di... Read more
Affected Products : jbig2dec- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7941
The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.... Read more
- Published: Apr. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7925
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HC... Read more
- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7859
FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.... Read more
Affected Products : ffmpeg- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7858
FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.... Read more
Affected Products : freetype- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7867
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function.... Read more
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7940
The iw_read_gif_file function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to consume an amount of available memory via a crafted file.... Read more
- Published: Apr. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7850
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.... Read more
Affected Products : nessus- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7951
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.... Read more
Affected Products : wondercms- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7861
Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.... Read more
Affected Products : grpc- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7870
LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx.... Read more
Affected Products : libreoffice- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025