Latest CVE Feed
-
7.8
HIGHCVE-2017-6251
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler where a missing permissions check may allow users to gain access to arbitrary physical system memory, which may lead to an escalation of privileges.... Read more
- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11720
There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.... Read more
Affected Products : lame- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11722
The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was inconsistent with its ... Read more
Affected Products : graphicsmagick- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-11694
MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with Apache Solr may be able to obtain or modify sens... Read more
Affected Products : medhost_document_management_system- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-11693
MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modi... Read more
Affected Products : medhost_document_management_system- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11719
The dnxhd_decode_header function in libavcodec/dnxhddec.c in FFmpeg 3.0 through 3.3.2 allows remote attackers to cause a denial of service (out-of-array access) or possibly have unspecified other impact via a crafted DNxHD file.... Read more
Affected Products : ffmpeg- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11718
There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.... Read more
Affected Products : metinfo- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11717
MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier for remote attackers to bypass intended challenge requirements by modifying the client-server data stream, as demonstrated by the login/findpass page.... Read more
Affected Products : metinfo- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11716
MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.... Read more
Affected Products : metinfo- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11715
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving admin/system/saf... Read more
Affected Products : metinfo- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11714
psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document, rela... Read more
- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11706
The Boozt Fashion application before 2.3.4 for Android allows remote attackers to read login credentials by sniffing the network and leveraging the lack of SSL. NOTE: the vendor response, before the application was changed to enable SSL logins, was "At th... Read more
Affected Products : boozt- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11705
A memory leak was found in the function parseSWF_SHAPEWITHSTYLE in util/parser.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.... Read more
Affected Products : ming- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11704
A heap-based buffer over-read was found in the function decompileIF in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.... Read more
Affected Products : ming- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11703
A memory leak vulnerability was found in the function parseSWF_DOACTION in util/parser.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.... Read more
Affected Products : ming- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11647
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to stored cross-site scripting attacks. Creating an SSID with an XSS payload results in successful exploitation.... Read more
- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11646
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by using administration.html to disable the firewall. They does not contain any token that can mitigate CSRF vuln... Read more
- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11645
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 do not require authentication for logfile.html, status.html, or system_config.html.... Read more
- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11184
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.... Read more
Affected Products : glpi- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11183
front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.... Read more
Affected Products : glpi- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025