Latest CVE Feed
-
9.8
CRITICALCVE-2017-11384
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN-4561.... Read more
Affected Products : control_manager- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11383
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-4560.... Read more
Affected Products : control_manager- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9770
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse that can cause an out of bounds read operation to occur due to a field within the IOCTL data being used as a length.... Read more
Affected Products : razer_synapse- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9769
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process.... Read more
Affected Products : synapse- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9467
Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via un... Read more
Affected Products : pan-os- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9459
Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecifie... Read more
Affected Products : pan-os- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9247
Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to launch processes with elevated privileges.... Read more
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9244
Cross-site scripting (XSS) vulnerability in the Trello app before 4.0.8 for iOS might allow remote attackers to inject arbitrary web script or HTML by uploading and attaching a crafted photo to a Card.... Read more
Affected Products : trello- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8390
The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via a crafted domain name.... Read more
Affected Products : pan-os- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7890
The GIF decoding function gdImageCreateFromGifCtx in gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.31 and 7.x before 7.1.7, does not zero colorMap arrays before use. A specially crafted GIF image could use the uninitialized... Read more
Affected Products : php- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7642
The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable.... Read more
Affected Products : vagrant_vmware_fusion- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11438
GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.... Read more
Affected Products : gitlab- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11437
GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.... Read more
Affected Products : gitlab- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11356
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control.... Read more
Affected Products : pega_platform- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11355
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or ... Read more
Affected Products : pega_platform- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
4.4
MEDIUMCVE-2017-11334
The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest ram ... Read more
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10806
Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.... Read more
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10664
qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.... Read more
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-8264
Untrusted search path vulnerability in F-Secure Online Scanner allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as F-SecureOnlineScanner.exe.... Read more
Affected Products : f-secure_online_scanner- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2015-7891
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory errors by leveraging definition of g2d_lock and g2d_unlock lock macros as no-ops... Read more
Affected Products : samsung_mobile- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025