Latest CVE Feed
-
9.8
CRITICALCVE-2017-14493
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.... Read more
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2783
An exploitable heap corruption vulnerability exists in the FillRowFormat functionality of Antenna House DMC HTMLFilter that is shipped with MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An... Read more
Affected Products : marklogic- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14510
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLeadCapture functionality is found vulnerable to unauthenticated cross-site scripting (XSS) attacks. This att... Read more
Affected Products : sugarcrm- Published: Sep. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14604
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In o... Read more
- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2780
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. To tr... Read more
Affected Products : matrixssl- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14727
logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.... Read more
- Published: Sep. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14865
There is a heap-based buffer overflow in the Exiv2::us2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.... Read more
Affected Products : exiv2- Published: Sep. 29, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2793
An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker... Read more
Affected Products : marklogic- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14939
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calculation, which allows remote attackers to cause a denial of service (heap-based buffer over-read and applic... Read more
Affected Products : binutils- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14989
A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the application via a crafted font file, because the FT_Done_Glyph function (from FreeType 2) is called at an incorrect place in the ImageMagi... Read more
Affected Products : imagemagick- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14992
Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, a... Read more
Affected Products : docker- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2794
An exploitable stack-based buffer overflow vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted PPT file can cause a stack corruption resulting in arbitrary code execution. An ... Read more
Affected Products : marklogic- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-2831
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitr... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
6.9
MEDIUMCVE-2017-15102
The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs aft... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15116
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15121
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.... Read more
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15232
libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.... Read more
Affected Products : libjpeg-turbo- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2798
An exploitable heap corruption vulnerability exists in the GetIndexArray functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker ... Read more
Affected Products : marklogic- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2888
An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-15265
Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted /dev/snd/seq ioctl calls, related to sound/core/seq/seq_clientmgr... Read more
Affected Products : linux_kernel- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025