Latest CVE Feed
-
6.1
MEDIUMCVE-2012-6705
Cross Site Scripting (XSS) exists in Jamroom before 4.2.7 via the Status Update field.... Read more
Affected Products : jamroom- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9417
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.... Read more
- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9416
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.... Read more
Affected Products : odoo- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-3741
In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation.... Read more
- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-3740
In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.... Read more
Affected Products : active_protection_system- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-8231
In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.... Read more
Affected Products : lenovo_service_bridge- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-8230
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.... Read more
Affected Products : lenovo_service_bridge- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8229
A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed.... Read more
Affected Products : lenovo_service_bridge- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8228
In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.... Read more
Affected Products : lenovo_service_bridge- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9409
In ImageMagick 7.0.5-5, the ReadMPCImage function in mpc.c allows attackers to cause a denial of service (memory leak) via a crafted file.... Read more
Affected Products : imagemagick- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9408
In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.... Read more
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9407
In ImageMagick 7.0.5-5, the ReadPALMImage function in palm.c allows attackers to cause a denial of service (memory leak) via a crafted file.... Read more
Affected Products : imagemagick- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9406
In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.... Read more
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9405
In ImageMagick 7.0.5-5, the ReadICONImage function in icon.c:452 allows attackers to cause a denial of service (memory leak) via a crafted file.... Read more
Affected Products : imagemagick- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9404
In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.... Read more
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9403
In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file.... Read more
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-0896
Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organ... Read more
Affected Products : zulip_server- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9380
OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.... Read more
Affected Products : openemr- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9379
Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and the from or to parameter to core\admin\modules\dashboard\vitals-statistics\404\create-301.php.... Read more
Affected Products : bigtree_cms- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9378
BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete before a... Read more
Affected Products : bigtree_cms- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025