Latest CVE Feed
-
8.8
HIGHCVE-2017-12598
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 8-opencv-invali... Read more
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12299
A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall Services that could allow an unauthenticated, remote attacker to send traffic to the local IP address of the device, by... Read more
Affected Products : firepower_extensible_operating_system- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.7
MEDIUMCVE-2017-12333
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software images. An authe... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-12345
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client ... Read more
Affected Products : data_center_network_manager- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12356
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of... Read more
Affected Products : jabber- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12344
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client ... Read more
Affected Products : data_center_network_manager- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12357
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected ... Read more
Affected Products : unified_communications_manager- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-12367
A "Cisco WebEx Network Recording Player Denial of Service Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user wi... Read more
Affected Products : webex_meetings_server- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12314
A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to the device availability, confidentiality, and integrity, aka Insecure Li... Read more
Affected Products : findit_network_discovery_utility- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12355
A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause one of the LPTS processes on an affected system to restart unexpectedly,... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.7
MEDIUMCVE-2017-12317
The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the ... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-12360
A vulnerability in Cisco WebEx Network Recording Player for WebEx Recording Format (WRF) files could allow an attacker to cause a denial of service (DoS) condition. An attacker could exploit this vulnerability by providing a user with a malicious WRF file... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2017-12351
A vulnerability in the guest shell feature of Cisco NX-OS System Software could allow an authenticated, local attacker to read and send packets outside the scope of the guest shell container. An attacker would need valid administrator credentials to perfo... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2017-12339
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker cou... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12366
A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient input validation of some parameters... Read more
Affected Products : webex_meeting_center- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12441
The row_is_empty function in base/4bitmap.c:274 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.... Read more
Affected Products : minidjvu- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-12478
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass authentication and execute arbitrary commands ... Read more
Affected Products : unitrends_backup- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12429
In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service.... Read more
Affected Products : imagemagick- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12420
Heap-based buffer overflow in the SMB implementation in NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allows remote authenticated users to cause a denial of service or execute arbitrary code.... Read more
Affected Products : clustered_data_ontap- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12430
In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadMPCImage in coders/mpc.c, which allows attackers to cause a denial of service.... Read more
Affected Products : imagemagick- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025