Latest CVE Feed
-
10.0
HIGHCVE-2017-7110
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged con... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7089
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) att... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-7138
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Directory Utility" component. It allows local users to discover the Apple ID of the computer's owner.... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7091
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" co... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-7112
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged con... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-7114
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary cod... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-7144
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie mishandling.... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7117
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" co... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7133
An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "MobileBackup" component. It allows remote attackers to obtain sensitive cleartext information in opportunistic circumstances by leveraging read access to... Read more
Affected Products : iphone_os- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-7115
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of serv... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7129
An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remot... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-5577
The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 does not set an errno value upon certain overflow detections, which allows local users to cause a denial of service (incorrect pointer d... Read more
Affected Products : linux_kernel- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5572
An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host database.... Read more
Affected Products : xenserver- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5671
Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak atta... Read more
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5592
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.... Read more
Affected Products : profanity- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5597
In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the DHCPv6 dissector could go into a large loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dhcpv6.c by changing a data type to avoid an integer o... Read more
Affected Products : wireshark- Published: Jan. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5651
In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the pro... Read more
Affected Products : tomcat- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5575
SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the modules parameter.... Read more
Affected Products : genixcms- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-5634
The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended "Please select booking identification" UI step, and obtain administrative privileges and network access on the underlying Windows OS, ... Read more
Affected Products : norwegian_air_kiosk- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5590
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.... Read more
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025