Latest CVE Feed
-
6.1
MEDIUMCVE-2017-12948
Core\Admin\PFTemplater.php in the PressForward plugin 4.3.0 and earlier for WordPress has XSS in the PATH_INFO to wp-admin/admin.php, related to PHP_SELF.... Read more
Affected Products : pressforward- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12963
There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix (available from ... Read more
Affected Products : libsass- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12953
The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted gig file.... Read more
Affected Products : libgig- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12981
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.... Read more
Affected Products : nexusphp- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12994
The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12950
The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.... Read more
Affected Products : libgig- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12993
The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c, several functions.... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13009
The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_print().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12969
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method... Read more
Affected Products : ip_office_contact_center- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12989
The RESP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-resp.c:resp_get_length().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-13136
The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference.... Read more
Affected Products : libbpg- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12971
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.... Read more
Affected Products : apache2triad- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-12982
The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/open... Read more
Affected Products : openjpeg- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12970
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts via a request to phpsftpd/users.php.... Read more
Affected Products : apache2triad- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13020
The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().... Read more
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13049
The Rx protocol parser in tcpdump before 4.9.2 has a buffer over-read in print-rx.c:ubik_print().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-12977
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploi... Read more
Affected Products : photo_gallery- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12991
The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13017
The DHCPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-dhcp6.c:dhcp6opt_print().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-13064
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.... Read more
- Published: Aug. 22, 2017
- Modified: Apr. 20, 2025