Latest CVE Feed
-
5.9
MEDIUMCVE-2017-15085
It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.... Read more
- Published: Nov. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15088
plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application cra... Read more
Affected Products : kerberos_5- Published: Nov. 23, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-15096
A flaw was found in GlusterFS in versions prior to 3.10. A null pointer dereference in send_brick_req function in glusterfsd/src/gf_attach.c may be used to cause denial of service.... Read more
Affected Products : glusterfs- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15200
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15189
In Wireshark 2.4.0 to 2.4.1, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by adding decrements.... Read more
Affected Products : wireshark- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15250
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x000000000... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15196
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15220
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring. This allows remote attackers to execute arbitrary code.... Read more
Affected Products : vx_search- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15253
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "User Mode Write AV starting at PDF!xmlGetGlobalState+0x000000000007dff2."... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15243
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Possible Stack Corruption starting at PDF!xmlGetGlobalState+0x000000... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15192
In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by considering a case where not all of the BTATT packets have the same encapsulation level.... Read more
Affected Products : wireshark- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15268
Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-websock.c.... Read more
Affected Products : qemu- Published: Oct. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15186
Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.... Read more
Affected Products : ffmpeg- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15191
In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.... Read more
- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15275
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.... Read more
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15194
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.... Read more
Affected Products : cacti- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15208
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private project of another user.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15219
The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, and a templates Description field.... Read more
Affected Products : dotcms- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15236
Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted request to TCP port 3001, as demonstrated by config* files and extendword.txt.... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15204
In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project of another user.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025