Latest CVE Feed
-
7.8
HIGHCVE-2016-4293
Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office 2014 VP allow remote attackers to execute arbitrary code via a crafted Hangul Hcell Document (.cell) file.... Read more
Affected Products : hancom_office_2014- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-1219
Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.... Read more
Affected Products : garoon- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-5190
NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.... Read more
Affected Products : access_manager- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7982
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.... Read more
Affected Products : libplist- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7938
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument. An example threat model is au... Read more
Affected Products : dmitry_deepmagic_information_gathering_tool- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7692
SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mishandled in a popen call. It's possible to exploit this vulnerability to execute arbitrary shell commands o... Read more
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7283
An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the downloadFiles function in api/includes/restore.php.... Read more
Affected Products : enterprise_backup- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-7282
An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the... Read more
Affected Products : enterprise_backup- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6919
Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.... Read more
Affected Products : drupal- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7979
The cookie feature in the packet action API implementation in net/sched/act_api.c in the Linux kernel 4.11.x through 4.11-rc7 mishandles the tb nlattr array, which allows local users to cause a denial of service (uninitialized memory access and refcount u... Read more
Affected Products : linux_kernel- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7978
Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot. The Samsung ID is SVE-2017-8290.... Read more
Affected Products : samsung_mobile- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-7976
Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose function in jbig2_image.c during operations on a crafted .jb2 file, leading to a denial of service (application crash) or disclosure of s... Read more
Affected Products : jbig2dec- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2013-7463
The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic protection mechanisms via a chosen plaintext attack.... Read more
Affected Products : aescrypt- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7975
Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_build_huffman_table function in jbig2_huffman.c during operations on a crafted JBIG2 file, leading to a denial of service (application c... Read more
Affected Products : jbig2dec- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-7964
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process.... Read more
Affected Products : wre6505_firmware- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7963
The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption and application crash) via operations on long strings. NOTE: the vendor disputes this, stating "There is ... Read more
Affected Products : php- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7962
The iwgif_read_image function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.... Read more
- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7961
The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or po... Read more
Affected Products : libcroco- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7960
The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.... Read more
Affected Products : libcroco- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7948
Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via a crafted PostScript document.... Read more
Affected Products : ghostscript- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025