Latest CVE Feed
-
7.8
HIGHCVE-2016-10270
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 8" and libtiff/tif_read.c:523:22.... Read more
Affected Products : libtiff- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10269
LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6 and 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact vi... Read more
Affected Products : libtiff- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10268
tools/tiffcp.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (integer underflow and heap-based buffer under-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 78490" and libtiff/tif_u... Read more
Affected Products : libtiff- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10267
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8.... Read more
Affected Products : libtiff- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10266
LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_read.c:351:22.... Read more
Affected Products : libtiff- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7257
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.... Read more
Affected Products : cms_made_simple- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7256
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_summary parameter. Someone must login to conduct the attack.... Read more
Affected Products : cms_made_simple- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7255
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the attack.... Read more
Affected Products : cms_made_simple- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7243
Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake.... Read more
Affected Products : tinydtls- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7240
An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefore, an unauthenticated attacker may be able to exploit th... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5511
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based buffer overflow.... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5510
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an out-of-bounds write.... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5509
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an out-of-bounds write.... Read more
Affected Products : imagemagick- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-5508
Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF file.... Read more
Affected Products : imagemagick- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5507
Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote attackers to cause a denial of service (memory consumption) via vectors involving a pixel cache.... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5506
Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file.... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5337
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5336
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5335
The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5334
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certifica... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025