Latest CVE Feed
-
6.1
MEDIUMCVE-2017-14957
Stored XSS vulnerability via a comment in inc/conv.php in BlogoText before 3.7.6 allows an unauthenticated attacker to inject JavaScript. If the victim is an administrator, an attacker can (for example) change global settings or create/delete posts. It is... Read more
Affected Products : blogotext- Published: Oct. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14945
Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Possible Stack Corruption starting at KERNELBASE!RaiseException+0x0000000000000068."... Read more
- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15019
LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.... Read more
Affected Products : lame- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14976
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack.... Read more
- Published: Oct. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14964
In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300005c.... Read more
Affected Products : anti.virus- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15021
bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF... Read more
Affected Products : binutils- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14962
In IKARUS anti.virus before 2.16.18, the ntguard.sys driver contains an Out of Bounds Write vulnerability because of not validating input values from IOCtl 0x83000058, a related issue to CVE-2017-17112.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14979
Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read arbitrary files via modified pathnames in the s parameter to index.php, related to Lib/Admin/Action/TplAction.class.php and Lib/Ad... Read more
Affected Products : gxlcms- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14974
The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandle the failure of a certain canonicalization step, which allows remote attackers to cause a denial of service (NULL ... Read more
Affected Products : binutils- Published: Oct. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15009
PRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page), via the errormsg parameter.... Read more
Affected Products : prtg_network_monitor- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14981
Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtration of data (url in /mods/_standard/rss_feeds/edit_feed.php). An attacker could inject arbitrary HTML and script code into a browser in t... Read more
Affected Products : atutor- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15054
An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerability, an authenticated attacker has to tamper with param... Read more
Affected Products : teampass- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14980
Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.... Read more
Affected Products : syncbreeze- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15008
PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error handling for a %00 in the SRC attribute of an IMG element.... Read more
Affected Products : prtg_network_monitor- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15039
Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.... Read more
Affected Products : zurmo_crm- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15022
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the DW_AT_name data type, which allows remote attackers to cause a denial of service (bfd_hash_hash NULL pointer dereference, or out-... Read more
Affected Products : binutils- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15017
ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadOneMNGImage in coders/png.c.... Read more
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15051
Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web script or HTML via the (1) URL value of an item or (2) user log history. To exploit the vulnerability, the ... Read more
Affected Products : teampass- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15044
The default installation of DocuWare Fulltext Search server through 6.11 allows remote users to connect to and download searchable text from the embedded Solr service, bypassing DocuWare's access control features of the DocuWare user interfaces and API. A... Read more
Affected Products : fulltext_server- Published: Nov. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15100
An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends page, when checking the graph for a trend based on a su... Read more
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025