Latest CVE Feed
-
8.8
HIGHCVE-2017-12704
A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying ... Read more
Affected Products : webaccess- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12719
An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A remote attacker is able to execute code to dereference a pointer within the program causing the application to become unavailable.... Read more
Affected Products : webaccess- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12713
An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files and folders with ACLs that affect other users are allowed to be modified by non-administrator accounts.... Read more
Affected Products : webaccess- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12738
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow Cross-Site Scripting (XSS) attacks i... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12733
A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V1... Read more
- Published: Sep. 09, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-12735
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). An attacker who performs a Man-in-the-Middle attack between the LOGO! BM and other devices could potentially decrypt and modify network traffic.... Read more
- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-12756
Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.... Read more
Affected Products : extplorer- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-12740
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-th... Read more
Affected Products : logo\!_soft_comfort- Published: Dec. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12819
Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55.... Read more
Affected Products : sentinel_ldk_rte_firmware- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12780
The ReadData function in ebmlstring.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted mkv file.... Read more
- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
8.7
HIGHCVE-2017-12741
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.... Read more
Affected Products : simatic_s7-1500_software_controller_firmware simatic_et_200sp_firmware simatic_s7-1500_firmware simatic_tdc_cp51m1_firmware simatic_s7-300_firmware simatic_winac_rtx_2010_firmware simatic_s7-200_firmware simatic_s7-400pn_v6_firmware simatic_s7-400h_v6_firmware simatic_s7-400pn\/dp_v7_firmware +79 more products- Published: Dec. 26, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-12786
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when AC... Read more
Affected Products : noviware- Published: Aug. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12809
QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty CDROM device drive.... Read more
- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-12763
An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to local files.... Read more
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12814
Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long environment variable.... Read more
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12792
Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) linkname, (2) url, or (3) title param... Read more
Affected Products : nexusphp- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12892
Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.... Read more
Affected Products : pdf_compressor- Published: Aug. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12837
Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the cas... Read more
Affected Products : perl- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12798
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.... Read more
Affected Products : nexusphp- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12817
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.... Read more
Affected Products : internet_security- Published: Aug. 25, 2017
- Modified: Apr. 20, 2025