Latest CVE Feed
-
9.8
CRITICALCVE-2017-2800
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to trigger this vu... Read more
Affected Products : wolfssl- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2799
An exploitable heap corruption vulnerability exists in the AddSst functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker can sen... Read more
Affected Products : marklogic- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2798
An exploitable heap corruption vulnerability exists in the GetIndexArray functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker ... Read more
Affected Products : marklogic- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9217
systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section.... Read more
Affected Products : systemd- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9216
libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will crash (segmentation fault) when parsing an invalid file.... Read more
- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8314
Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.... Read more
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8313
Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.... Read more
Affected Products : vlc_media_player- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8312
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.... Read more
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8311
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file.... Read more
Affected Products : vlc_media_player- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8310
Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles fil... Read more
Affected Products : vlc_media_player- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0374
lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array.... Read more
Affected Products : config-model- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-0373
The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an unspecified impact via a crafted Debian package file... Read more
Affected Products : config-model- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9214
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.... Read more
Affected Products : enterprise_linux debian_linux openstack virtualization virtualization_manager openvswitch- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-3128
A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.... Read more
Affected Products : fortios- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2797
An exploitable heap overflow vulnerability exists in the ParseEnvironment functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6.... Read more
Affected Products : marklogic- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2794
An exploitable stack-based buffer overflow vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted PPT file can cause a stack corruption resulting in arbitrary code execution. An ... Read more
Affected Products : marklogic- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2793
An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker... Read more
Affected Products : marklogic- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2783
An exploitable heap corruption vulnerability exists in the FillRowFormat functionality of Antenna House DMC HTMLFilter that is shipped with MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An... Read more
Affected Products : marklogic- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6131
In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into the BIG-IP system. The impacted administrative account is the Azure instanc... Read more
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9212
The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name.... Read more
Affected Products : bluetooth_stack- Published: May. 23, 2017
- Modified: Apr. 20, 2025