Latest CVE Feed
-
6.6
MEDIUMCVE-2017-6325
The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect web applications that rely on a scripting run time. This issue is caused when an application builds a path ... Read more
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6324
The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentially malicious macro through despite the administrator having the 'disarm' functionality enabled. This constitutes a 'b... Read more
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9949
The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly rel... Read more
Affected Products : radare2- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8493
In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.... Read more
Affected Products : forticlient- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-3315
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4) /etc/os-releas... Read more
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-3215
The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as demonstrated by a value that does not account for the size of the IP options.... Read more
Affected Products : virtio-win- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2015-3142
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the ... Read more
Affected Products : automatic_bug_reporting_tool- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-1870
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.... Read more
Affected Products : automatic_bug_reporting_tool- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2014-8127
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw ... Read more
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9948
A stack buffer overflow vulnerability has been discovered in Microsoft Skype 7.2, 7.35, and 7.36 before 7.37, involving MSFTEDIT.DLL mishandling of remote RDP clipboard content within the message box.... Read more
Affected Products : skype- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-7496
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary directories.... Read more
Affected Products : arm_installer- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9145
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9937
In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.... Read more
Affected Products : libtiff- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9936
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.... Read more
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9935
In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bounds read in TIFFCleanup, an invali... Read more
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9929
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.... Read more
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9928
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.... Read more
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9615
Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.... Read more
Affected Products : moneyworks- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9466
The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to gain read-write access to system sett... Read more
- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7459
ntopng before 3.0 allows HTTP Response Splitting.... Read more
Affected Products : ntopng- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025