Latest CVE Feed
-
9.8
CRITICALCVE-2017-7230
A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrary code via a GET request.... Read more
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5673
In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS. Six files are affected: crypsis/layouts/message/item/default.php, crypsis/layouts/message/item/top/default.php, cryp... Read more
Affected Products : kunena- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7227
GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.... Read more
Affected Products : binutils- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-7226
The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses the strlen function instead of strnlen, leading to prog... Read more
Affected Products : binutils- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7225
The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both empty, triggering a NULL pointer dereference and an invalid write, and leading to a program crash.... Read more
Affected Products : binutils- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7224
The find_nearest_line function in objdump in GNU Binutils 2.28 is vulnerable to an invalid write (of size 1) while disassembling a corrupt binary that contains an empty function name, leading to a program crash.... Read more
Affected Products : binutils- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7223
GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of size 1) while attempting to unget an EOF character from the input stream, potentially leading to a program crash.... Read more
Affected Products : binutils- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6971
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka AlienVault... Read more
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
8.4
HIGHCVE-2017-6970
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen socket, aka AlienVault ID ENG-104863.... Read more
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9840
ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted palm file.... Read more
Affected Products : imagemagick- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-9839
magick/colormap-private.h in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds access).... Read more
Affected Products : imagemagick- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9838
magick/cache.c in ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service (crash).... Read more
Affected Products : imagemagick- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9836
ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a crafted xpm file.... Read more
Affected Products : imagemagick- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2014-9835
Heap overflow in ImageMagick 6.8.9-9 via a crafted wpf file.... Read more
Affected Products : imagemagick- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2014-9834
Heap overflow in ImageMagick 6.8.9-9 via a crafted pict file.... Read more
Affected Products : imagemagick- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2014-9833
Heap overflow in ImageMagick 6.8.9-9 via a crafted psd file.... Read more
Affected Products : imagemagick- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2014-9832
Heap overflow in ImageMagick 6.8.9-9 via a crafted pcx file.... Read more
Affected Products : imagemagick- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7222
A cross-site scripting (XSS) vulnerability in MantisBT before 2.1.1 allows remote attackers to inject arbitrary HTML or JavaScript (if MantisBT's CSP settings permit it) by modifying 'window_title' in the application configuration. This requires privilege... Read more
Affected Products : mantisbt- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5874
CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass authentication and insert XSS sequences or possibly have unspecified other impact.... Read more
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7215
Cross site scripting in some view elements in the index filter tool in app/webroot/js/misp2.4.68.js and the organisation landing page in app/View/Organisations/ajax/landingpage.ctp of MISP before 2.4.69 allows remote attackers to inject arbitrary web scri... Read more
- Published: Mar. 21, 2017
- Modified: Apr. 20, 2025