Latest CVE Feed
-
9.8
CRITICALCVE-2017-2800
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to trigger this vu... Read more
Affected Products : wolfssl- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2870
An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code execution. An attacker can send a fi... Read more
- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15576
Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive information.... Read more
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15592
An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because self-linear shadow mappings are mishandled for translated guests.... Read more
Affected Products : xen- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2801
A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparisons which could lead to certificate verification issues and abuse. A specially crafted X509 certificate would need to be delivered to th... Read more
Affected Products : botan- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15897
Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implemen... Read more
Affected Products : node.js- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15922
In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.... Read more
Affected Products : libextractor- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16364
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This issue is due to an untrusted pointer dereference whe... Read more
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16370
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs because of a computation that r... Read more
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16382
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs as a result of a computation th... Read more
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2808
An exploitable use-after-free vulnerability exists in the account parsing component of the Ledger-CLI 3.1.1. A specially crafted ledger file can cause a use-after-free vulnerability resulting in arbitrary code execution. An attacker can convince a user to... Read more
Affected Products : ledger- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16387
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs as a result of a computation th... Read more
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16393
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of a use after free vul... Read more
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16410
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is a result of untrusted input that is ... Read more
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2807
An exploitable buffer overflow vulnerability exists in the tag parsing functionality of Ledger-CLI 3.1.1. A specially crafted journal file can cause an integer underflow resulting in code execution. An attacker can construct a malicious journal file to tr... Read more
Affected Products : ledger- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16416
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a computation that writes ... Read more
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16516
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and ... Read more
- Published: Nov. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2789
When copying filedata into a buffer, JustSystems Ichitaro Office 2016 Trial will calculate two values to determine how much data to copy from the document. If both of these values are larger than the size of the buffer, the application will choose the sma... Read more
Affected Products : ichitaro- Published: Feb. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12983
Heap-based buffer overflow in the ReadSFWImage function in coders/sfw.c in ImageMagick 7.0.6-8 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.... Read more
Affected Products : imagemagick- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12978
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.... Read more
Affected Products : cacti- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025