Latest CVE Feed
-
7.5
HIGHCVE-2017-8294
libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function.... Read more
Affected Products : yara- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5186
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certi... Read more
- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-3066
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : coldfusion- Actively Exploited
- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3008
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a reflected cross-site scripting vulnerability.... Read more
Affected Products : coldfusion- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7415
Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.... Read more
- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8291
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April... Read more
- Actively Exploited
- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8289
Stack-based buffer overflow in the ipv6_addr_from_str function in sys/net/network_layer/ipv6/addr/ipv6_addr_from_str.c in RIOT prior to 2017-04-25 allows local attackers, and potentially remote attackers, to cause a denial of service or possibly have unsp... Read more
Affected Products : riot- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-8288
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the... Read more
Affected Products : gnome-shell- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8287
FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.... Read more
Affected Products : freetype- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6037
A Heap-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulnerability causes a buffer overflow when a maliciously crafted project file is run by the system.... Read more
Affected Products : levi_studio_hmi_editor- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6035
A Stack-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulnerability causes a buffer overflow, which could result in denial of service when a malicious project file is run on the system.... Read more
Affected Products : levi_studio_hmi_editor- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3162
HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0.... Read more
Affected Products : hadoop- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3161
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.... Read more
Affected Products : hadoop- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1170
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230.... Read more
Affected Products : websphere_commerce- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-8962
IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851.... Read more
Affected Products : bigfix_inventory- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
5.6
MEDIUMCVE-2016-8924
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's sessio... Read more
Affected Products : maximo_asset_management- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-8284
The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects ... Read more
Affected Products : qemu- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7720
Buffer overflow in PrivateTunnel 2.7 and 2.8 allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long password.... Read more
Affected Products : privatetunnel- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6054
A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The application uses a hard-coded decryption password to protect sensitive user information.... Read more
Affected Products : blue_link- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-6052
A Man-in-the-Middle issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. Communication channel endpoints are not verified, which may allow a remote attacker to access or influence communications between the identified endpoints.... Read more
Affected Products : blue_link- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025