Latest CVE Feed
-
6.7
MEDIUMCVE-2017-12317
The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the ... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-12360
A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by providing a user with a malicious WRF file... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2017-12351
A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticated, local attacker to read and send packets outside the scope of the guest shell container. An attacker would need valid administrator credentials to perfo... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2017-12339
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker cou... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12366
A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient input validation of some parameters... Read more
Affected Products : webex_meeting_center- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12441
The row_is_empty function in base/4bitmap.c:274 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.... Read more
Affected Products : minidjvu- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-12478
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass authentication and execute arbitrary commands ... Read more
Affected Products : unitrends_backup- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12429
In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service.... Read more
Affected Products : imagemagick- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12420
Heap-based buffer overflow in the SMB implementation in NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allows remote authenticated users to cause a denial of service or execute arbitrary code.... Read more
Affected Products : clustered_data_ontap- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12430
In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadMPCImage in coders/mpc.c, which allows attackers to cause a denial of service.... Read more
Affected Products : imagemagick- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12422
NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arbitrary objects via unspecified vectors.... Read more
Affected Products : storagegrid_webscale- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.7
HIGHCVE-2017-12423
NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on other Storage Virtual Machines (SVMs) via unspecified vectors.... Read more
Affected Products : clustered_data_ontap- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12433
In ImageMagick 7.0.6-1, a memory leak vulnerability was found in the function ReadPESImage in coders/pes.c, which allows attackers to cause a denial of service, related to ResizeMagickMemory in memory.c.... Read more
Affected Products : imagemagick- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12431
In ImageMagick 7.0.6-1, a use-after-free vulnerability was found in the function ReadWMFImage in coders/wmf.c, which allows attackers to cause a denial of service.... Read more
Affected Products : imagemagick- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12451
The _bfd_xcoff_read_ar_hdr function in bfd/coff-rs6000.c and bfd/coff64-rs6000.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds stack read via a ... Read more
Affected Products : binutils- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12424
In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This cr... Read more
- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12445
The JB2BitmapCoder::code_row_by_refinement function in jb2/bmpcoder.cpp in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.... Read more
Affected Products : minidjvu- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12457
The bfd_make_section_with_flags function in section.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a NULL dereference via a crafted file.... Read more
Affected Products : binutils- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12453
The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.... Read more
Affected Products : binutils- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12481
The find_option function in option.cc in Ledger 3.1.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.... Read more
Affected Products : ledger- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025