Latest CVE Feed
-
10.0
HIGHCVE-2017-11213
An issue was discovered in Adobe Flash Player 27.0.0.183 and earlier versions. This vulnerability occurs as a result of a computation that reads data that is past the end of the target buffer due to an integer overflow; the computation is part of the abst... Read more
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-2704
Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawe... Read more
Affected Products : smarthome hiapp hwparentcontrol hwparentcontrolparent crowdtest hiwallet huawei_pay skytone hwclouddrive\(emui6.0\) hwphonefinder\(emui6.0\) +4 more products- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11271
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EM... Read more
- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11280
Adobe Digital Editions 4.5.4 and earlier has an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : digital_editions- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2641
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.... Read more
Affected Products : moodle- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11282
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.... Read more
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11332
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2017-2721
Some Huawei smart phones with software Berlin-L21C10B130,Berlin-L21C185B133,Berlin-L21HNC10B131,Berlin-L21HNC185B140,Berlin-L21HNC432B151,Berlin-L22C636B160,Berlin-L22HNC636B130,Berlin-L22HNC675B150CUSTC675D001,Berlin-L23C605B131,Berlin-L24HNC567B110,FRD-... Read more
Affected Products : berlin-l21_firmware berlin-l21hn_firmware berlin-l22_firmware berlin-l22hn_firmware berlin-l23_firmware berlin-l24hn_firmware frd-l02_firmware frd-l04_firmware frd-l09_firmware frd-l14_firmware +12 more products- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11407
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt.... Read more
- Published: Jul. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11449
coders/mpc.c in ImageMagick before 7.0.6-1 does not enable seekable streams and thus cannot validate blob sizes, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an image received... Read more
Affected Products : imagemagick- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11450
coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via JPEG data that is too short.... Read more
- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11473
Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local users to gain privileges via a crafted ACPI table.... Read more
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-11523
The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop) via a crafted file, because the end-of-file condition is not considered.... Read more
Affected Products : imagemagick- Published: Jul. 22, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-11526
The ReadOneMNGImage function in coders/png.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted file.... Read more
Affected Products : imagemagick- Published: Jul. 23, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-11530
The ReadEPTImage function in coders/ept.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.... Read more
Affected Products : imagemagick- Published: Jul. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11547
The resample_gauss function in resample.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mid file. NOTE: a crash might be relevant when using the --background option. NOTE: the TiMidit... Read more
Affected Products : timidity\+\+- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11591
There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11628
In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_parser.c could cause a denial of service or potentially allow executing code. NOTE: this is only relevant for ... Read more
Affected Products : php- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11640
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to an address access exception in the WritePTIFImage() function in coders/tiff.c.... Read more
Affected Products : imagemagick- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11729
A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1440) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.... Read more
Affected Products : ming- Published: Jul. 29, 2017
- Modified: Apr. 20, 2025