Latest CVE Feed
-
6.5
MEDIUMCVE-2017-9287
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.... Read more
- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-3011
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable integer overflow vulnerability in the CCITT fax PDF filter. Successful exploitation could lead to arbitrary code execution.... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-3035
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable use after free vulnerability in the XML Forms Architecture (XFA) engine. Successful exploitation could lead to arbitrary code executi... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9375
QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing.... Read more
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-3021
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability in the JPEG 2000 parser engine.... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2017-2866
An exploitable vulnerability exists in the /api/CONFIG/backup functionality of Circle with Disney. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.... Read more
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2810
An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnera... Read more
Affected Products : tablib- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-2680
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.... Read more
Affected Products : simatic_s7-1500_software_controller_firmware scalance_m-800_firmware scalance_s615_firmware scalance_x408_firmware scalance_x300_firmware scalance_x414_firmware simatic_et_200sp_firmware simatic_s7-1500_firmware scalance_x200_firmware simatic_cp_1243-1_firmware +192 more products- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2543
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Multi-Touch" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via... Read more
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2469
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-2442
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaScript Bindings" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2433
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2413
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "QuickTime" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) ... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2405
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit Web Inspector" component. It allows remote attackers to execute arbitrary code or cause a denial of service (mem... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2392
An issue was discovered in certain Apple products. Safari before 10.1 is affected. The issue involves the "WebKit" component. It allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted app.... Read more
Affected Products : safari- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2849
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during NTP server configuration resulting in command injection. ... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2845
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2846
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injecti... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17935
The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet that trigg... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17912
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region.... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025