Latest CVE Feed
-
7.8
HIGHCVE-2017-0005
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges ... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_vista windows_10_1607 windows_10_1507 +1 more products- Actively Exploited
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0001
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges ... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_vista windows_10_1607 windows_10_1507 +1 more products- Actively Exploited
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6952
Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or possibly have unspecified other impact via a large value.... Read more
Affected Products : capstone- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6951
The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.... Read more
Affected Products : linux_kernel- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-6949
An issue was discovered in CHICKEN Scheme through 4.12.0. When using a nonstandard CHICKEN-specific extension to allocate an SRFI-4 vector in unmanaged memory, the vector size would be used in unsanitised form as an argument to malloc(). With an unexpecte... Read more
Affected Products : chicken- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5857
Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_UNREF commands... Read more
Affected Products : qemu- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5856
Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist ... Read more
- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5667
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vectors in... Read more
- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-5643
Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.... Read more
Affected Products : camel- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-5617
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.... Read more
- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-5505
The jas_matrix_asl function in jas_seq.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.... Read more
Affected Products : jasper- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10187
The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.... Read more
Affected Products : calibre- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-0770
Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable.... Read more
Affected Products : connections_business_directory_plugin- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8981
Heap-based buffer overflow in the PdfParser::ReadXRefSubsection function in base/PdfParser.cpp in PoDoFo allows attackers to have unspecified impact via vectors related to m_offsets.size.... Read more
Affected Products : podofo- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6510
Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker to list and download any file from any folder outside the FTP root Directory.... Read more
Affected Products : easy_file_sharing_ftp_server- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-6381
A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution. This is mitigated by the default .htaccess protection against PHP execution, and the fact that Composer development dependencies aren'... Read more
Affected Products : drupal- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6379
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.... Read more
Affected Products : drupal- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6377
When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.... Read more
Affected Products : drupal- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10247
Buffer overflow in the my_getline function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.... Read more
- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10246
Buffer overflow in the main function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.... Read more
- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025