Latest CVE Feed
-
7.8
HIGHCVE-2017-14572
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV starting at Unknown Symbol @ 0x000000000479049b called from Unknown Symbol @ 0x000000000d89645b."... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14561
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to an "Illegal Instruction Violation starting at Unknown Symbol @ 0x00000000048c024d called from STDUXPSFile!DllUnregisterServer+0... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-14600
Pragyan CMS v3.0 is vulnerable to an Error-Based SQL injection in cms/admin.lib.php via $_GET['del_black'], resulting in Information Disclosure.... Read more
Affected Products : pragyan_cms- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14556
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "User Mode Write AV starting at STDUDjVuFile!DllUnregisterServer+0x000000000000da27."... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14579
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "Read Access Violation on Control Flow starting at STDUJBIG2File!DllGetClassObject+0x0000000000005b70."... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14569
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to a "Read Access Violation starting at STDUXPSFile!DllUnregisterServer+0x0000000000005bd5."... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14610
bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for... Read more
Affected Products : bareos- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14573
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to an "Illegal Instruction Violation starting at Unknown Symbol @ 0x00000000030c024c called from STDUXPSFile!DllUnregisterServer+0... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14580
XnView Classic for Windows Version 2.41 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at jbig2dec+0x000000000000870f."... Read more
- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14603
In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffer contents and when combined with t... Read more
- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14587
The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter.... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14628
In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp.... Read more
Affected Products : sam2p- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14653
member/Orderinfo.asp in ASP4CMS AspCMS 2.7.2 allows remote authenticated users to read arbitrary order information via a modified OrderNo parameter.... Read more
Affected Products : aspcms- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14583
NetApp Clustered Data ONTAP versions 9.x prior to 9.1P10 and 9.2P2 are susceptible to a vulnerability which allows an attacker to cause a Denial of Service (DoS) in SMB environments.... Read more
Affected Products : clustered_data_ontap- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14596
In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.... Read more
Affected Products : joomla\!- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14588
Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14586
The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at or above version 4.0 and before version 4.30 are affected by this vulnerability.... Read more
Affected Products : hipchat- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-14582
The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a self-signed certificate.... Read more
Affected Products : site24x7_mobile_network_poller- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-14651
WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.... Read more
Affected Products : api_manager identity_server enterprise_integrator app_manager application_server business_process_server business_rules_server complex_event_processor dashboard_server data_analytics_server +7 more products- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-14607
In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.... Read more
- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025