Latest CVE Feed
-
7.0
HIGHCVE-2017-6874
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behav... Read more
Affected Products : linux_kernel- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6780
A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to cause the system to consume additional memory, eventually forcing the device to restart, aka Memory Exhaustion.... Read more
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6837
WAVE.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via vectors related to a large number of coefficients.... Read more
Affected Products : audiofile- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6838
Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.... Read more
Affected Products : audiofile- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6793
A vulnerability in the Inventory Management feature of Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to view sensitive information on the system. The vulnerability is due to insufficient protection of restricted... Read more
Affected Products : prime_collaboration_provisioning- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6797
A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'action_type' parameter.... Read more
Affected Products : mantisbt- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6812
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.vote.php (id parameter).... Read more
Affected Products : mangoswebv4- Published: Mar. 11, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6830
Heap-based buffer overflow in the alaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.... Read more
Affected Products : audiofile- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6789
A vulnerability in the Cisco Unified Intelligence Center web interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing a Document Object Model (DOM)-based, environment or client-side cross-site scripting ... Read more
Affected Products : unified_intelligence_center- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-6873
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the integrated web server on port 443/... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-6795
A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite arbitrary files on the underlying operating system of an affected device.... Read more
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-6868
An Improper Authentication issue was discovered in Siemens SIMATIC CP 44x-1 RNA, all versions prior to 1.4.1. An unauthenticated remote attacker may be able to perform administrative actions on the Communication Process (CP) of the RNA series module, if n... Read more
Affected Products : simatic_cp_44x-1_redundant_network_access_modules- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6802
An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.... Read more
- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6817
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.... Read more
- Published: Mar. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6807
mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.... Read more
Affected Products : mod_auth_mellon- Published: Mar. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6886
An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.... Read more
Affected Products : libraw- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-6988
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "802.1X" component. It allows remote attackers to discover the network credentials of arbitrary users by operating a crafted network that requires ... Read more
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6809
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.donate.php (id parameter).... Read more
Affected Products : mangoswebv4- Published: Mar. 11, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6850
The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.... Read more
Affected Products : jasper- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6871
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, th... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025