Latest CVE Feed
-
10.0
CRITICALCVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.... Read more
Affected Products : qemu- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8608
The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.... Read more
Affected Products : perl- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2015-8763
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-bounds read.... Read more
Affected Products : freeradius- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-8900
The ReadHDRImage function in coders/hdr.c in ImageMagick 6.x and 7.x allows remote attackers to cause a denial of service (infinite loop) via a crafted HDR file.... Read more
Affected Products : imagemagick- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2015-8984
The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed pattern, which triggers an out-of-bounds read.... Read more
Affected Products : glibc- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2015-8985
The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to extended regular expression processing.... Read more
Affected Products : glibc- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-0762
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack pos... Read more
- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-10060
The ConcatenateImages function in MagickWand/magick-cli.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.... Read more
Affected Products : imagemagick- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10064
Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10109
Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.... Read more
- Published: Feb. 23, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2016-10151
The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment vari... Read more
Affected Products : hesiod- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10167
The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.... Read more
Affected Products : libgd- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10187
The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.... Read more
Affected Products : calibre- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10199
The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.... Read more
Affected Products : gstreamer- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2107
Untrusted search path vulnerability in Self-extracting archive files created by 7-ZIP32.DLL 9.22.00.01 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : 7-zip32.dll- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-2099
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote code execution via unspecified vectors.... Read more
Affected Products : appgoat- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2112
TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-... Read more
Affected Products : ts-ptcam\/poe_firmware ts-ptcam_firmware ts-wrlc_firmware ts-wlc2_firmware ts-wlce_firmware ts-wptcam2_firmware ts-wptcam_firmware ts-ptcam\/poe ts-ptcam ts-wrlc +4 more products- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
CRITICALCVE-2017-2292
Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.safe_load on input. This has been tested in all Puppet-sup... Read more
Affected Products : mcollective- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-1550
An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92. An attacker can send a series of crafted messages to attempt to recover the message digest key.... Read more
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
2.6
LOWCVE-2017-2109
Cybozu KUNAI for Android 3.0.4 to 3.0.5.1 allow remote attackers to obtain log information through a malicious Android application.... Read more
Affected Products : kunai- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025