Latest CVE Feed
-
8.8
HIGHCVE-2017-15016
ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadEnhMetaFile in coders/emf.c.... Read more
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-14925
Cross-Site Request Forgery (CSRF) vulnerability via IMG element in Tiki before 16.3, 17.x before 17.1, 12 LTS before 12.12 LTS, and 15 LTS before 15.5 LTS allows an authenticated user to edit global permissions if an administrator opens a wiki page with a... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-15037
In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can cause t2p->t_name strings to lack a final '\0' character.... Read more
Affected Products : freebsd- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14928
In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.... Read more
- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14941
Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit... Read more
Affected Products : jasperreports- Published: Oct. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14935
Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive information.... Read more
Affected Products : pulse_one_on-premise- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14954
The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local users to obtain sensitive information, and bypass the KASLR protection mechanism, via a crafted system ca... Read more
Affected Products : linux_kernel- Published: Oct. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14932
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file.... Read more
Affected Products : binutils- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14934
process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file that contains a negative size value in... Read more
Affected Products : binutils- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-14930
Memory leak in decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.... Read more
Affected Products : binutils- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14944
Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.... Read more
Affected Products : proget- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14957
Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript. If the victim is an administrator, an attacker can (for example) change global settings or create/delete posts. It is... Read more
Affected Products : blogotext- Published: Oct. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14945
Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Possible Stack Corruption starting at KERNELBASE!RaiseException+0x0000000000000068."... Read more
- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15019
LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.... Read more
Affected Products : lame- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14976
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack.... Read more
- Published: Oct. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14964
In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300005c.... Read more
Affected Products : anti.virus- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15021
bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF... Read more
Affected Products : binutils- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14962
In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Out of Bounds Write vulnerability because of not validating input values from IOCtl 0x83000058, a related issue to CVE-2017-17112.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14979
Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read arbitrary files via modified pathnames in the s parameter to index.php, related to Lib/Admin/Action/TplAction.class.php and Lib/Ad... Read more
Affected Products : gxlcms- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14974
The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandle the failure of a certain canonicalization step, which allows remote attackers to cause a denial of service (NULL ... Read more
Affected Products : binutils- Published: Oct. 02, 2017
- Modified: Apr. 20, 2025