Latest CVE Feed
-
5.5
MEDIUMCVE-2017-2671
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by... Read more
Affected Products : linux_kernel- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10799
When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().... Read more
Affected Products : graphicsmagick- Published: Jul. 03, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-2691
Huawei P9 versions earlier before EVA-AL10C00B373, versions earlier before EVA-CL00C92B373, versions earlier before EVA-DL00C17B373, versions earlier before EVA-TL00C01B373 have a lock-screen bypass vulnerability. An unauthenticated attacker could force t... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-2703
Phone Finder in versions earlier before MHA-AL00BC00B156,Versions earlier before MHA-CL00BC00B156,Versions earlier before MHA-DL00BC00B156,Versions earlier before MHA-TL00BC00B156,Versions earlier before EVA-AL10C00B373,Versions earlier before EVA-CL10C00... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-10911
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fie... Read more
Affected Products : linux_kernel- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-10928
In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandl... Read more
Affected Products : imagemagick- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10979
An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.... Read more
Affected Products : freeradius- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2644
In Moodle 3.x, XSS can occur via evidence of prior learning.... Read more
Affected Products : moodle- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11107
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.... Read more
- Published: Jul. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11109
Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance.... Read more
Affected Products : vim- Published: Jul. 08, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-11147
In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile functio... Read more
- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11213
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abst... Read more
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-2704
Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawe... Read more
Affected Products : smarthome hiapp hwparentcontrol hwparentcontrolparent crowdtest hiwallet huawei_pay skytone hwclouddrive\(emui6.0\) hwphonefinder\(emui6.0\) +4 more products- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11271
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EM... Read more
- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11280
Adobe Digital Editions 4.5.4 and earlier has an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : digital_editions- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2641
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.... Read more
Affected Products : moodle- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11282
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.... Read more
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11332
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2017-2721
Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-... Read more
Affected Products : berlin-l21_firmware berlin-l21hn_firmware berlin-l22_firmware berlin-l22hn_firmware berlin-l23_firmware berlin-l24hn_firmware frd-l02_firmware frd-l04_firmware frd-l09_firmware frd-l14_firmware +12 more products- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11407
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt.... Read more
- Published: Jul. 18, 2017
- Modified: Apr. 20, 2025