Latest CVE Feed
-
4.7
MEDIUMCVE-2017-1284
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow a local user with ability to run or enable trace, to obtain sensitive information from WebSphere Application Server traces including user credentials. IBM X-Force ID: 125145.... Read more
- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-11147
In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile functio... Read more
- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11145
In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsing code could be used by attackers able to supply date strings to leak information from the interpreter, related to ext/date/lib/parse_... Read more
Affected Products : php- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11144
In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, the openssl extension PEM sealing code did not check the return value of the OpenSSL sealing function, which could lead to a crash of the PHP interpreter, related to an interpretation confli... Read more
Affected Products : php- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11143
In PHP before 5.6.31, an invalid free in the WDDX deserialization of boolean parameters could be used by attackers able to inject XML for deserialization to crash the PHP interpreter, related to an invalid free for an empty boolean element in ext/wddx/wdd... Read more
Affected Products : php- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11142
In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting long form variables, related to main/php_variables.c.... Read more
Affected Products : php- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10397
In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used by attackers to bypass hostname-specific URL checks, as demonstrated by evil.example.com:80#@good.example.com/ and evil.example.com:80... Read more
Affected Products : php- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-11141
The ReadMATImage function in coders\mat.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call.... Read more
Affected Products : imagemagick- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-11140
The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remote attackers to cause a denial of service (resource consumption) via crafted JPEG files.... Read more
Affected Products : graphicsmagick- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11139
GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.... Read more
- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11126
The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the "block_type != 2" case, ... Read more
Affected Products : mpg123- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11125
libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_get_path function in util.c.... Read more
Affected Products : xar- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11124
libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_unserialize function in archive.c.... Read more
Affected Products : xar- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-8003
EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. A remote authenticated high privileged user may potentially exploit this vulnerability to access unauthorized information from the underlying OS server by supplying speciall... Read more
Affected Products : data_protection_advisor- Published: Jul. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8002
EMC Data Protection Advisor prior to 6.4 contains multiple blind SQL injection vulnerabilities. A remote authenticated attacker may potentially exploit these vulnerabilities to gain information about the application by causing execution of arbitrary SQL c... Read more
Affected Products : data_protection_advisor- Published: Jul. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-4976
EMC ESRS Policy Manager prior to 6.8 contains an undocumented account (OpenDS admin) with a default password. A remote attacker with the knowledge of the default password may login to the system and gain administrator privileges to the local LDAP director... Read more
Affected Products : esrs_policy_manager- Published: Jul. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11113
In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.... Read more
Affected Products : ncurses- Published: Jul. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11112
In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.... Read more
Affected Products : ncurses- Published: Jul. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11111
In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.... Read more
- Published: Jul. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11110
The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted file, i.e., data is written to memory addresses ... Read more
- Published: Jul. 08, 2017
- Modified: Apr. 20, 2025