Latest CVE Feed
-
7.1
HIGHCVE-2017-1000061
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service... Read more
Affected Products : xmlsec- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1000099
When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers. The code doing this would send the wrong buffer to the user (stdout or the application's provide callback), which could... Read more
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2536
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a ... Read more
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-1000379
The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. Linux Kernel version 4.11.5 is affected.... Read more
Affected Products : linux_kernel- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1000128
Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser... Read more
Affected Products : exiv2- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-1000229
Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.... Read more
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-10004
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
8.4
HIGHCVE-2017-2583
The load_segment_descriptor implementation in arch/x86/kvm/emulate.c in the Linux kernel before 4.9.5 improperly emulates a "MOV SS, NULL selector" instruction, which allows guest OS users to cause a denial of service (guest OS crash) or gain guest OS pri... Read more
Affected Products : linux_kernel- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-10062
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Oracle Java Web Console). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastruc... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-10086
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols... Read more
Affected Products : debian_linux active_iq_unified_manager cloud_backup oncommand_balance oncommand_insight oncommand_performance_manager oncommand_unified_manager jdk jre e-series_santricity_os_controller +9 more products- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2578
In Moodle 3.x, there is XSS in the assignment submission page.... Read more
Affected Products : moodle- Published: Jan. 20, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-10114
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protoco... Read more
Affected Products : debian_linux active_iq_unified_manager cloud_backup oncommand_balance oncommand_insight oncommand_performance_manager oncommand_unified_manager jdk jre e-series_santricity_os_controller +9 more products- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2017-10143
Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthentica... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10162
Vulnerability in the Siebel Core - Server Framework component of Oracle Siebel CRM (subcomponent: Services). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HT... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-10192
Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthentica... Read more
Affected Products : istore- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-2576
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.... Read more
Affected Products : moodle- Published: Jan. 20, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-10237
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure... Read more
Affected Products : vm_virtualbox- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10267
Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and 12.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access... Read more
Affected Products : tuxedo- Published: Nov. 14, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-10277
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Net). Supported versions that are affected are 6.9.9 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple pr... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-10349
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated ... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025