Latest CVE Feed
-
9.0
HIGHCVE-2015-8257
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.sht... Read more
Affected Products : network_camera_firmware cannon_network_camera explosion-protected_camera fixed_box_camera fixed_bullet_camera fixed_dome_camera modular_camera onboard_camera panoramic_camera ptz_camera +1 more products- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8403
360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password. This affects firmware 2.1.4. Exploitation can... Read more
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8401
In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in the function png_load() in lib/png.c:724. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS.... Read more
Affected Products : swftools- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8400
In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load() in lib/png.c:755. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS; it might cause arb... Read more
Affected Products : swftools- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6565
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. As no sanitization checks are in place, an attacker can... Read more
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6564
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive sys... Read more
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8399
PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."... Read more
Affected Products : pcre2- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8398
dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during dumping of debug information from a corrupt binary. This vulnerability causes programs that conduct an analysis of binary programs, such as objdump and readelf, to crash.... Read more
Affected Products : binutils- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8397
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 and an invalid write of size 1 during processing of a corrupt binary containing reloc(s) with negative addresses. This v... Read more
Affected Products : binutils- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8396
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing reloc offset range tests didn't catch small negative offsets less than the size of the reloc field.... Read more
Affected Products : binutils- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8395
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid write of size 8 because of missing a malloc() return-value check to see if memory had actually been allocated in the _bfd_generic_get_s... Read more
Affected Products : binutils- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8394
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 4 due to NULL pointer dereferencing of _bfd_elf_large_com_section. This vulnerability causes programs that conduct an anal... Read more
Affected Products : binutils- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8393
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcopy and strip, that SHT_REL/SHR_RELA sections are always n... Read more
Affected Products : binutils- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8392
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL in the _bfd_dwarf2_find_nearest_line function. This vul... Read more
Affected Products : binutils- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8388
GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.... Read more
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8377
GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.... Read more
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-8376
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.... Read more
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6128
An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager big-ip_websafe +11 more products- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5631
An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.... Read more
Affected Products : caseaware- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8385
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.... Read more
Affected Products : craft_cms- Published: May. 01, 2017
- Modified: Apr. 20, 2025