Latest CVE Feed
-
6.5
MEDIUMCVE-2017-11539
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the ReadOnePNGImage() function in coders/png.c.... Read more
Affected Products : imagemagick- Published: Jul. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11548
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file.... Read more
Affected Products : libao- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11536
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteJP2Image() function in coders/jp2.c.... Read more
Affected Products : imagemagick- Published: Jul. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11562
A Session Fixation Vulnerability exists in the MT4 Networks SenhaSegura Web Application 2.2.23.8 via login_if.php.... Read more
Affected Products : senhasegura- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11576
FontForge 20161012 does not ensure a positive size in a weight vector memcpy call in readcfftopdict (parsettf.c) resulting in DoS via a crafted otf file.... Read more
Affected Products : fontforge- Published: Jul. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11553
There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26. A crafted input will lead to remote denial of service.... Read more
Affected Products : exiv2- Published: Jul. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11772
The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information discl... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11571
FontForge 20161012 is vulnerable to a stack-based buffer overflow in addnibble (parsettf.c) resulting in DoS or code execution via a crafted otf file.... Read more
Affected Products : fontforge- Published: Jul. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11673
Reporter.exe in Acunetix 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed PRE file, related to a "User Mode Write AV starting at reporter!madTraceProcess."... Read more
Affected Products : web_vulnerability_scanner- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11568
FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafted otf file.... Read more
Affected Products : fontforge- Published: Jul. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11582
dayrui FineCms 5.0.9 has SQL Injection via the num parameter in an action=related or action=tags request to libraries/Template.php.... Read more
Affected Products : finecms- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11570
FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.... Read more
Affected Products : fontforge- Published: Jul. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11641
GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent Cache (MPC) files.... Read more
Affected Products : graphicsmagick- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11651
NexusPHP V1.5 has XSS via a javascript: or data: URL in a UBBCode url tag.... Read more
Affected Products : nexusphp- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11605
There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack.... Read more
Affected Products : libsass- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11684
There is an illegal address access in the build_table function in libavcodec/bitstream.c of Libav 12.1 that will lead to remote denial of service via crafted input.... Read more
Affected Products : libav- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11588
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is remote command execution via shell metacharacters in the pingAddr paramete... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11614
MEDHOST Connex contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient... Read more
Affected Products : connex- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11696
Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file.... Read more
Affected Products : network_security_services- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11589
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control for info.html, wancfg.cmd, rtroutecfg.cmd, arpview.cmd, ... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025