Latest CVE Feed
-
7.8
HIGHCVE-2017-17472
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82730030.... Read more
Affected Products : vir.it_explorer- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17501
WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.... Read more
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17515
etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indic... Read more
- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17475
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82736068.... Read more
Affected Products : vir.it_explorer- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17498
WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (bit_stream.c MagickBitStreamMSBWrite heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted fil... Read more
Affected Products : graphicsmagick- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17479
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.... Read more
Affected Products : openjpeg- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17522
Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software ma... Read more
Affected Products : python- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17500
ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file.... Read more
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17525
guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.... Read more
Affected Products : postbooks- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-17507
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.... Read more
Affected Products : hdf5- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-17506
In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.... Read more
Affected Products : hdf5- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17598
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.... Read more
Affected Products : affiliate_mlm_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17514
boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates t... Read more
- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17530
common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: this is disputed by a t... Read more
Affected Products : geomview- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-17553
The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vulnerability could allow attackers to abuse this implementation through a malicious Intent URI, in order to invoke private Activities wi... Read more
Affected Products : dolphin- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17509
In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.... Read more
Affected Products : hdf5- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17533
default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indicated ... Read more
Affected Products : tkabber- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17589
FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter.... Read more
Affected Products : thumbtack_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17526
Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.... Read more
Affected Products : giac- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17535
lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.... Read more
Affected Products : gjots2- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025