Latest CVE Feed
-
5.3
MEDIUMCVE-2017-10192
Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthentica... Read more
Affected Products : istore- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-2576
In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.... Read more
Affected Products : moodle- Published: Jan. 20, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-10237
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure... Read more
Affected Products : vm_virtualbox- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10267
Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and 12.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access... Read more
Affected Products : tuxedo- Published: Nov. 14, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-10277
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Net). Supported versions that are affected are 6.9.9 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple pr... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-10349
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated ... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-10378
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.11 and earlier. Easily exploitable vulnerability allows low privileged a... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10388
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthent... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-2643
In Moodle 3.2.x, global search displays user names for unauthenticated users.... Read more
Affected Products : moodle- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2017-10411
Vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerabil... Read more
Affected Products : knowledge_management- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-10622
An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based attacker to login as any privileged user. This issue only affects Junos Space Network Management Platform 1... Read more
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-10661
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queuei... Read more
- Published: Aug. 19, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-2671
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by... Read more
Affected Products : linux_kernel- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10799
When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().... Read more
Affected Products : graphicsmagick- Published: Jul. 03, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-2691
Huawei P9 versions earlier before EVA-AL10C00B373, versions earlier before EVA-CL00C92B373, versions earlier before EVA-DL00C17B373, versions earlier before EVA-TL00C01B373 have a lock-screen bypass vulnerability. An unauthenticated attacker could force t... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-2703
Phone Finder in versions earlier before MHA-AL00BC00B156,Versions earlier before MHA-CL00BC00B156,Versions earlier before MHA-DL00BC00B156,Versions earlier before MHA-TL00BC00B156,Versions earlier before EVA-AL10C00B373,Versions earlier before EVA-CL10C00... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-10911
The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fie... Read more
Affected Products : linux_kernel- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-10928
In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandl... Read more
Affected Products : imagemagick- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10979
An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.... Read more
Affected Products : freeradius- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2644
In Moodle 3.x, XSS can occur via evidence of prior learning.... Read more
Affected Products : moodle- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025