Latest CVE Feed
-
7.8
HIGHCVE-2017-6843
Heap-based buffer overflow in the PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.... Read more
Affected Products : podofo- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7033
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "afclip" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via... Read more
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6846
The GraphicsStack::TGraphicsStackElement::SetNonStrokingColorSpace function in graphicsstack.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.... Read more
Affected Products : podofo- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6844
Buffer overflow in the PoDoFo::PdfParser::ReadXRefSubsection function in PdfParser.cpp in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.... Read more
Affected Products : podofo- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6862
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR... Read more
Affected Products : wnr2000v5_firmware wnr2000v4_firmware wnr2000v3_firmware wnr2000v5 wnr2000v4 wnr2000v3- Actively Exploited
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6869
A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web ... Read more
Affected Products : viewport_for_web_office_portal- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6866
A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.2) that could allow an authenticated low-privileged remote user to gain read access to data in the XHQ solution exceeding his configured permission level.... Read more
Affected Products : xhq_server- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-6867
A vulnerability was discovered in Siemens SIMATIC WinCC (V7.3 before Upd 11 and V7.4 before SP1), SIMATIC WinCC Runtime Professional (V13 before SP2 and V14 before SP1), SIMATIC WinCC (TIA Portal) Professional (V13 before SP2 and V14 before SP1) that coul... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-6870
A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol implementation could allow an attacker to read and modify data within a TLS session while performing a Man-in-the-Mid... Read more
Affected Products : simatic_wincc_sm\@rtclient- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6892
In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.... Read more
Affected Products : libsndfile- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6884
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to exe... Read more
- Actively Exploited
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6953
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields. There may be a risk of local code execution with untrusted input to SmartDiag.exe or SymDiag.exe.... Read more
Affected Products : smartdiag_diagnosis_tool- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6877
Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim 0.7.1 and earlier allows remote attackers to inject arbitrary web script.... Read more
Affected Products : lutim- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6891
Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a specially crafted assignments file via the e.g. asn1Coding ... Read more
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6887
A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple ... Read more
Affected Products : libraw- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6908
An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (fID) passed to the "concrete5-legacy-master/web/concrete/tools/files/selector_data.php" URL. An attacker could execute arbitrar... Read more
Affected Products : concrete5- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6895
USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml.... Read more
Affected Products : usb_pratirodh- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6978
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibility Framework" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory cor... Read more
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-6915
CSRF exists in BigTree CMS 4.1.18 with the colophon parameter to the admin/settings/update/ page. The Colophon can be changed.... Read more
Affected Products : bigtree_cms- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7011
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof the address bar via a crafted web site that uses FRAME eleme... Read more
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025