Latest CVE Feed
-
7.5
HIGHCVE-2017-17847
An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message, aka TBE-01-021. This is demonstra... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-17886
In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadPSDChannelZip in coders/psd.c, which allows attackers to cause a denial of service via a crafted psd image file.... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17846
An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily long strings, aka TBE-01-003.... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17854
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overflow and memory corruption) or possibly have unspecified other impact by leveraging unrestricted integer values for pointer arithmetic.... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-17849
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.... Read more
Affected Products : getgo_download_manager- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17852
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of 32-bit ALU ops.... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-17885
In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadPICTImage in coders/pict.c, which allows attackers to cause a denial of service via a crafted PICT image file.... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17903
FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.... Read more
Affected Products : lynda_clone- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-17862
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users for d... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17869
The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter.... Read more
Affected Products : mgl-instagram-gallery- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17866
pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have u... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-17878
An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka the CONFIG_FEATURE_DEFAULT_PASSWD_ALGO="des" setting).... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17894
Readymade Job Site Script has CSRF via the /job URI.... Read more
Affected Products : basic_job_site_script- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-17884
In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in the function WriteOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted PNG image file.... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17907
PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename parameter.... Read more
Affected Products : car_rental_script- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17913
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use a different structure type.... Read more
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-17916
SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this meth... Read more
- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-17924
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin/review_userwise.php.... Read more
Affected Products : professional_service_script- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-17919
SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this met... Read more
Affected Products : ruby_on_rails- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-17910
On Hoermann BiSecur devices before 2018, a vulnerability can be exploited by recording a single radio transmission. An attacker can intercept an arbitrary radio frame exchanged between a BiSecur transmitter and a receiver to obtain the encrypted packet an... Read more
Affected Products : hs5-868-bs_firmware hse2-868-bs_firmware hse1-868-bs_firmware hs5-868-bs hse2-868-bs hse1-868-bs- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025