Latest CVE Feed
-
7.8
HIGHCVE-2017-15263
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!x... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15212
In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private project of another user.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15252
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "Read Access Violation on Block Data Move starting at PDF!xmlListWalk+0x0000000000015... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUM- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15256
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!x... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15226
Zyxel NBG6716 V1.00(AAKG.9)C0 devices allow command injection in the ozkerz component because beginIndex and endIndex are used directly in a popen call.... Read more
- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15222
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.... Read more
Affected Products : nftp- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15381
SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).... Read more
Affected Products : e-sic- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15235
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename.... Read more
Affected Products : groupware- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-15272
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to e... Read more
Affected Products : psftpd- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15302
In CPUID CPU-Z through 1.81, there are improper access rights to a kernel-mode driver (e.g., cpuz143_x64.sys for version 1.43) that can result in information disclosure or elevation of privileges, because of an arbitrary read of any physical address via i... Read more
Affected Products : cpu-z- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-15223
Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an infinite loop.... Read more
Affected Products : mini_mail_server- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15246
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "Read Access Violation on Block Data Move starting at PDF!xmlListWalk+0x0000000000015... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15225
_bfd_dwarf2_cleanup_debug_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory leak) via a crafted ELF file.... Read more
Affected Products : binutils- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15238
ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage.... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15249
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlGetGlobalState+0x0000... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15273
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as titles in internal artefacts.... Read more
Affected Products : mahara- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15269
The PSFTPd 10.0.4 Build 729 server does not prevent FTP bounce scans by default. These can be performed using "nmap -b" and allow performing scans via the FTP server.... Read more
Affected Products : psftpd- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15278
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context ... Read more
Affected Products : teampass- Published: Oct. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15277
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that ... Read more
- Published: Oct. 12, 2017
- Modified: Apr. 20, 2025