Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2017-17472

    TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82730030.... Read more

    Affected Products : vir.it_explorer
    • Published: Dec. 08, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17501

    WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.... Read more

    Affected Products : debian_linux graphicsmagick
    • Published: Dec. 11, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17515

    etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indic... Read more

    Affected Products : debian_linux metview
    • Published: Dec. 14, 2017
    • Modified: Apr. 20, 2025
  • 7.8

    HIGH
    CVE-2017-17475

    TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82736068.... Read more

    Affected Products : vir.it_explorer
    • Published: Dec. 08, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17498

    WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (bit_stream.c MagickBitStreamMSBWrite heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted fil... Read more

    Affected Products : graphicsmagick
    • Published: Dec. 11, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-17479

    In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.... Read more

    Affected Products : openjpeg
    • Published: Dec. 08, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17522

    Lib/webbrowser.py in Python through 3.6.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software ma... Read more

    Affected Products : python
    • Published: Dec. 14, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17500

    ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file.... Read more

    Affected Products : debian_linux graphicsmagick
    • Published: Dec. 11, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17525

    guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.... Read more

    Affected Products : postbooks
    • Published: Dec. 14, 2017
    • Modified: Apr. 20, 2025
  • 6.5

    MEDIUM
    CVE-2017-17507

    In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.... Read more

    Affected Products : hdf5
    • Published: Dec. 11, 2017
    • Modified: Apr. 20, 2025
  • 6.5

    MEDIUM
    CVE-2017-17506

    In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.... Read more

    Affected Products : hdf5
    • Published: Dec. 11, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-17598

    Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.... Read more

    Affected Products : affiliate_mlm_script
    • Published: Dec. 13, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17514

    boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates t... Read more

    Affected Products : debian_linux nip2
    • Published: Dec. 14, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17530

    common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: this is disputed by a t... Read more

    Affected Products : geomview
    • Published: Dec. 14, 2017
    • Modified: Apr. 20, 2025
  • 5.3

    MEDIUM
    CVE-2017-17553

    The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vulnerability could allow attackers to abuse this implementation through a malicious Intent URI, in order to invoke private Activities wi... Read more

    Affected Products : dolphin
    • Published: Dec. 12, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17509

    In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.... Read more

    Affected Products : hdf5
    • Published: Dec. 11, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17533

    default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indicated ... Read more

    Affected Products : tkabber
    • Published: Dec. 14, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-17589

    FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parameter.... Read more

    Affected Products : thumbtack_clone
    • Published: Dec. 13, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17526

    Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.... Read more

    Affected Products : giac
    • Published: Dec. 14, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-17535

    lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.... Read more

    Affected Products : gjots2
    • Published: Dec. 14, 2017
    • Modified: Apr. 20, 2025
Showing 20 of 294745 Results