Latest CVE Feed
-
9.0
HIGHCVE-2017-16921
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands... Read more
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16892
In Bftpd before 4.7, there is a memory leak in the file rename function.... Read more
Affected Products : bftpd- Published: Nov. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16944
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character signifyi... Read more
- Published: Nov. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16952
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.... Read more
Affected Products : kmplayer- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-16899
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_te... Read more
- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14560
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at STDUXPSFile!DllUnregisterServer+0x00000000000... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14512
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an editforum action, a different vulnerability than CVE-2017-12981.... Read more
Affected Products : nexusphp- Published: Sep. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14550
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to a "Possible Stack Corruption starting at STDUDjVuFile!DllUnregisterServer+0x000000000000e8b8."... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14558
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "User Mode Write AV starting at STDUDjVuFile!DllUnregisterServer+0x0000000000018cc2."... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14497
The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other imp... Read more
- Published: Sep. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14539
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x000000000011d767.... Read more
Affected Products : irfanview- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14507
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timel... Read more
Affected Products : content_timeline- Published: Sep. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14553
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "User Mode Write AV starting at STDUDjVuFile!DllUnregisterServer+0x00000000000085f5."... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14520
In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.... Read more
Affected Products : poppler- Published: Sep. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14541
XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x000000000001f2... Read more
- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14534
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.... Read more
Affected Products : nexusphp- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-14530
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.... Read more
Affected Products : crony_cronjob_manager- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-14531
ImageMagick 7.0.7-0 has a memory exhaustion issue in ReadSUNImage in coders/sun.c.... Read more
- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14544
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .epub file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at STDUEPu... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14542
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .epub file, related to a "Read Access Violation on Block Data Move starting at STDUEPubFile!DllUnregisterServer+0x0000000000010262."... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025