Latest CVE Feed
-
9.8
CRITICALCVE-2017-12939
A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.... Read more
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12935
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c.... Read more
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12964
There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp. It will lead to a remote denial of service attack.... Read more
Affected Products : libsass- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12930
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.... Read more
Affected Products : dlx_spot_player4- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12948
Core\Admin\PFTemplater.php in the PressForward plugin 4.3.0 and earlier for WordPress has XSS in the PATH_INFO to wp-admin/admin.php, related to PHP_SELF.... Read more
Affected Products : pressforward- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12963
There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix (available from ... Read more
Affected Products : libsass- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12953
The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted gig file.... Read more
Affected Products : libgig- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12981
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.... Read more
Affected Products : nexusphp- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12994
The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12950
The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.... Read more
Affected Products : libgig- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12993
The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c, several functions.... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13009
The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_print().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12969
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method... Read more
Affected Products : ip_office_contact_center- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12989
The RESP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-resp.c:resp_get_length().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-13136
The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference.... Read more
Affected Products : libbpg- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12971
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.... Read more
Affected Products : apache2triad- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-12982
The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/open... Read more
Affected Products : openjpeg- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12970
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts via a request to phpsftpd/users.php.... Read more
Affected Products : apache2triad- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13020
The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().... Read more
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13049
The Rx protocol parser in tcpdump before 4.9.2 has a buffer over-read in print-rx.c:ubik_print().... Read more
Affected Products : tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025