Latest CVE Feed
-
7.5
HIGHCVE-2017-16953
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.... Read more
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-16852
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signatu... Read more
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16907
In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.... Read more
Affected Products : groupware- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-16933
etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.... Read more
Affected Products : icinga- Published: Nov. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16931
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name.... Read more
Affected Products : libxml2- Published: Nov. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16951
Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, or AIF file.... Read more
Affected Products : winamp_pro- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16894
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in s... Read more
Affected Products : laravel- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16877
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.... Read more
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16882
Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain pri... Read more
Affected Products : icinga- Published: Nov. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16893
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data fr... Read more
Affected Products : piwigo- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16938
A global buffer overflow in OptiPNG 0.7.6 allows remote attackers to cause a denial-of-service attack or other unspecified impact with a maliciously crafted GIF format file, related to an uncontrolled loop in the LZWReadByte function of the gifread.c file... Read more
- Published: Nov. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17027
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.... Read more
Affected Products : qts- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16895
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.... Read more
Affected Products : arq- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16904
The Public tologin feature in admin.php in LvyeCMS through 3.1 allows XSS via a crafted username that is mishandled during later log viewing by an administrator.... Read more
Affected Products : lvyecms- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-16921
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands... Read more
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16892
In Bftpd before 4.7, there is a memory leak in the file rename function.... Read more
Affected Products : bftpd- Published: Nov. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16944
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character signifyi... Read more
- Published: Nov. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16952
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.... Read more
Affected Products : kmplayer- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-16899
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_te... Read more
- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14560
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at STDUXPSFile!DllUnregisterServer+0x00000000000... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025