Latest CVE Feed
-
6.5
MEDIUMCVE-2017-13732
There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.... Read more
Affected Products : ncurses- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-13674
Symantec ProxyClient 3.4 for Windows is susceptible to a privilege escalation vulnerability. A malicious local Windows user can, under certain circumstances, exploit this vulnerability to escalate their privileges on the system and execute arbitrary code ... Read more
Affected Products : proxyclient- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13725
The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().... Read more
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-13672
QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.... Read more
- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-13663
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.... Read more
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-13693
The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and byp... Read more
Affected Products : linux_kernel- Published: Aug. 25, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-13684
Unisys Libra 64xx and 84xx and FS601 class systems with MCP-FIRMWARE before 43.211 allow remote authenticated users to cause a denial of service (program crash) or have unspecified other impact via vectors related to incorrect literal handling, which trig... Read more
Affected Products : mcp-firmware- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-13747
There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service attack.... Read more
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-13699
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent in cleartext as a POST parameter. An attacker could reve... Read more
- Published: Nov. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-13734
There is an illegal address access in the _nc_safe_strcat function in strings.c in ncurses 6.0 that will lead to a remote denial of service attack.... Read more
Affected Products : ncurses- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-13700
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface.... Read more
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-13746
There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack.... Read more
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13701
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Indeed passwords are stored without being ciphered with a timestamped ciphering ... Read more
- Published: Nov. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-13724
On the Axesstel MU553S MU55XS-V1.14, there is a Stored Cross Site Scripting vulnerability in the APN parameter under the "Basic Settings" page.... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2017-13706
XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote authenticated users to obtain sensitive information, cause a denial of service, conduct server-side request ... Read more
Affected Products : lansweeper- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-13780
The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows directory traversal attacks for reading arbitrary files via the module/admin_conf/download.php file parameter.... Read more
Affected Products : eyesofnetwork- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-13708
Buffer overflow in the web server service in VX Search Enterprise 10.0.14 allows remote attackers to execute arbitrary code via a crafted GET request.... Read more
Affected Products : vx_search- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-13738
There is an illegal address access in the _lou_getALine function in compileTranslationTable.c:346 in Liblouis 3.2.0.... Read more
Affected Products : liblouis- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-13731
There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack.... Read more
Affected Products : ncurses- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-13722
In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could be used by local attackers authenticated to an Xserver for a buffer over-read, for information disclosure o... Read more
Affected Products : libxfont- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025