Latest CVE Feed
-
9.3
HIGHCVE-2017-2233
Untrusted search path vulnerability in Installer of PDF Digital Signature Plugin (G2.30) and earlier, distributed till June 29, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : pdf_digital_signature- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-2255
Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".... Read more
Affected Products : garoon- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2227
Untrusted search path vulnerability in The installer of Charamin OMP Version 1.1.7.4 and earlier, Version 1.2.0.0 Beta and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : omp- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2220
Untrusted search path vulnerability in Installer of CASL II simulator (self-extract format) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : casl_ii_simulator- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2016-4323
A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide a... Read more
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2232
Untrusted search path vulnerability in Installer of Shinseiyo Sogo Soft (4.8A) and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : shinseiyo_sogo_soft- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2238
Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows remote attackers to hijack the authentication of ... Read more
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-4456
The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem.... Read more
Affected Products : gnutls- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-2240
Directory traversal vulnerability in AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to read arbitrary files via "File Transfer Web Service".... Read more
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2289
Untrusted search path vulnerability in Installer of Qua station connection tool for Windows version 1.00.03 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4490
Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to inconsistent use of the long and int types for lengths.... Read more
Affected Products : libiberty- Published: Feb. 24, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2252
Untrusted search path vulnerability in self-extracting archive files created by File Compact Ver.5 version 5.10 and earlier, Ver.6 version 6.02 and earlier, Ver.7 version 7.02 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an ... Read more
Affected Products : file_compact- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-2290
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. ... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16935
Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restrictions via a direct request to /plugins/core-ui/servercomm/messages.xml, as demonstrated by changing the ... Read more
Affected Products : ametys- Published: Nov. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17104
Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].... Read more
Affected Products : fiyo_cms- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16906
In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action.... Read more
Affected Products : groupware- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16943
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.... Read more
- Published: Nov. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-17054
In aubio 0.4.6, a divide-by-zero error exists in the function new_aubio_source_wavread() in source_wavread.c, which may lead to DoS when playing a crafted audio file.... Read more
Affected Products : aubio- Published: Nov. 29, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-17081
The gmc_mmx function in libavcodec/x86/mpegvideodsp.c in FFmpeg 2.3 and 3.4 does not properly validate widths and heights, which allows remote attackers to cause a denial of service (integer signedness error and out-of-array read) via a crafted MPEG file.... Read more
Affected Products : ffmpeg- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16898
The printMP3Headers function in util/listmp3.c in libming v0.4.8 or earlier is vulnerable to a global buffer overflow, which may allow attackers to cause a denial of service via a crafted file, a different vulnerability than CVE-2016-9264.... Read more
Affected Products : libming- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025