Latest CVE Feed
-
7.0
HIGHCVE-2017-6051
An Uncontrolled Search Path Element issue was discovered in BLF-Tech LLC VisualView HMI Version 9.9.14.0 and prior. The uncontrolled search path element vulnerability has been identified, which may allow an attacker to run a malicious DLL file within the ... Read more
Affected Products : visualview_hmi- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8825
A null dereference vulnerability has been found in the MIME handling component of LibEtPan before 1.8, as used in MailCore and MailCore 2. A crash can occur in low-level/imf/mailimf.c during a failed parse of a Cc header containing multiple e-mail address... Read more
Affected Products : libetpan- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8847
The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8846
The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive.... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8845
The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8844
The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8843
The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8842
The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive.... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8833
Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development version from github."... Read more
Affected Products : zen_cart- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUM- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
6.9
MEDIUMCVE-2017-8831
The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact by changing a certain sequenc... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8830
In ImageMagick 7.0.5-6, the ReadBMPImage function in bmp.c:1379 allows attackers to cause a denial of service (memory leak) via a crafted file.... Read more
Affected Products : imagemagick- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8829
Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with a crafted YAML file.... Read more
Affected Products : lintian- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-8827
forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8804
The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcomm... Read more
Affected Products : glibc- Published: May. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8391
The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file during operating system installation, which allows local users to obtain sensitive information by reading ... Read more
- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-7929
An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to access restricted files or directories.... Read more
Affected Products : webaccess- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7927
A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-... Read more
- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7925
A Password in Configuration File issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HC... Read more
- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7923
A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 1... Read more
- Published: May. 06, 2017
- Modified: Apr. 20, 2025