Latest CVE Feed
-
9.8
CRITICALCVE-2017-17699
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.... Read more
Affected Products : antivirus- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17714
Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, the /re... Read more
Affected Products : trape- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17719
A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the result_message parameter to includes/concours_page.php.... Read more
Affected Products : wp-concours- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17739
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.... Read more
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17730
DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.... Read more
Affected Products : dedecms- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17740
contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd cras... Read more
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17738
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html.... Read more
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-17747
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-17819
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in asm/preproc.c that will cause a remote denial of service attack, because pointers associated with skip_white_ calls are not validated.... Read more
- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17787
In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-17763
SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK injection.... Read more
Affected Products : superbeam- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-17760
OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is used.... Read more
- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17752
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17780
The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notificatio... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17928
PHP Scripts Mall Professional Service Script has SQL injection via the admin/review.php id parameter.... Read more
Affected Products : professional_service_script- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17784
In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17793
Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read backup archives on Windows servers, by providing the ar... Read more
Affected Products : blogotext- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17795
In IKARUS anti.virus 2.16.20, the driver file (ntguard.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83000088.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17800
In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8273A0A0, a different vulnerability... Read more
Affected Products : vir.it_explorer- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17809
In Golden Frog VyprVPN before 2.15.0.5828 for macOS, the vyprvpnservice launch daemon has an unprotected XPC service that allows attackers to update the underlying OpenVPN configuration and the arguments passed to the OpenVPN binary when executed. An atta... Read more
Affected Products : vyprvpn- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025