Latest CVE Feed
-
5.4
MEDIUMCVE-2017-1106
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : curam_social_program_management- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7686
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server ... Read more
Affected Products : ignite- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5241
Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in the "Name" and "Description" fields of a Workspace, as well as the "Description" field of a File Details pane of a ... Read more
Affected Products : secure_file_transfer- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9998
The _dwarf_decode_s_leb128_chk function in dwarf_leb.c in libdwarf through 2017-06-28 allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.... Read more
Affected Products : libdwarf- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9996
The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial of se... Read more
Affected Products : ffmpeg- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9995
libavcodec/scpr.c in FFmpeg 3.3 before 3.3.1 does not properly validate height and width data, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a cr... Read more
Affected Products : ffmpeg- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9994
libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow and a... Read more
- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9993
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist data.... Read more
- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9992
Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application crash)... Read more
- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9991
Heap-based buffer overflow in the xwd_decode_frame function in libavcodec/xwddec.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (applicatio... Read more
Affected Products : ffmpeg- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9990
Stack-based buffer overflow in the color_string_to_rgba function in libavcodec/xpmdec.c in FFmpeg 3.3 before 3.3.1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file.... Read more
Affected Products : ffmpeg- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9989
util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack.... Read more
- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9988
The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c.... Read more
- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9987
There is a heap-based buffer overflow in the function hpel_motion in mpegvideo_motion.c in libav 12.1. A crafted input can lead to a remote denial of service attack.... Read more
Affected Products : libav- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9986
The intr function in sound/oss/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer betwee... Read more
Affected Products : linux_kernel- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9985
The snd_msndmidi_input_read function in sound/isa/msnd/msnd_midi.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue... Read more
- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9984
The snd_msnd_interrupt function in sound/isa/msnd/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue ... Read more
Affected Products : linux_kernel- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9445
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved in... Read more
Affected Products : systemd- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6086
Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.15 allow remote attackers to hijack the authentication of logged administrators to (1) add an administrator user via a crafted POST requ... Read more
Affected Products : vimbadmin- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2491
Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remote attackers to execute arbitrary code via a crafted web page, or a crafted file.... Read more
Affected Products : iphone_os- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025