Latest CVE Feed
-
6.5
MEDIUMCVE-2017-11640
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to an address access exception in the WritePTIFImage() function in coders/tiff.c.... Read more
Affected Products : imagemagick- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11729
A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1440) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.... Read more
Affected Products : ming- Published: Jul. 29, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2701
Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the application, it could be exploited to ... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11935
Microsoft Office 2016 Click-to-Run (C2R) allows a remote code execution vulnerability due to the way files are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".... Read more
Affected Products : office- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11755
The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an AcquireSemaphoreInfo call.... Read more
Affected Products : imagemagick- Published: Jul. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2688
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the targeted user has an active session and is induced into clicki... Read more
Affected Products : ruggedcom_rox_i- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11762
The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vu... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11786
Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016 allows an attacker to steal an authentication hash that can be reused elsewhere, due to how Skype for Business handles authentication requests, aka "Skype for Business Elevation of ... Read more
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2696
The emerg_data driver in CAM-L21C10B130 and earlier versions, CAM-L21C185B141 and earlier versions has a buffer overflow vulnerability. An attacker with the root privilege of the Android system can tricks a user into installing a malicious application on ... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11810
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the co... Read more
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11821
ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". ... Read more
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2694
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be pl... Read more
Affected Products : vmall- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2017-2683
A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripting (XSS) attack, potentially resulting in obtaining administrative permissions.... Read more
Affected Products : ruggedcom_network_management_software- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11843
ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 a... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-2702
Phone Finder in versions earlier before MHA-AL00C00B170 can be bypass. An attacker can bypass the Phone Finder by special steps and obtain the owner of the phone.... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11873
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "S... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2689
Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or change configuration settings.... Read more
Affected Products : ruggedcom_rox_i- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2017-15707
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.... Read more
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11894
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and and Internet Explorer adn Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows ... Read more
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11912
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Serv... Read more
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025