Latest CVE Feed
-
6.5
MEDIUMCVE-2017-6210
The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process crash) by destroying context 0 (zero).... Read more
Affected Products : virglrenderer- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6209
Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU proc... Read more
Affected Products : virglrenderer- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6060
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.... Read more
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-5994
Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter.... Read more
Affected Products : virglrenderer- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5993
Memory leak in the vrend_renderer_init_blit_ctx function in vrend_blitter.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_CCMD_BLIT commands.... Read more
Affected Products : virglrenderer- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5938
Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.... Read more
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5584
Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecif... Read more
Affected Products : pan-os- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5583
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to read arbitrary files via unspecified vectors.... Read more
Affected Products : pan-os- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6906
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression buffer.... Read more
Affected Products : libgd- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10251
Integer overflow in the jpc_pi_nextcprl function in jpc_t2cod.c in JasPer before 1.900.20 allows remote attackers to have unspecified impact via a crafted file, which triggers use of an uninitialized value.... Read more
Affected Products : jasper- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10250
The jp2_colr_destroy function in jp2_cod.c in JasPer before 1.900.13 allows remote attackers to cause a denial of service (NULL pointer dereference) by leveraging incorrect cleanup of JP2 box data on error. NOTE: this vulnerability exists because of an in... Read more
Affected Products : jasper- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10249
Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.12 allows remote attackers to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow.... Read more
Affected Products : jasper- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10248
The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) via vectors involving an empty sequence.... Read more
Affected Products : jasper- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6909
An issue was discovered in Shimmie <= 2.5.1. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "shimmie2-master/ext/chatbox/history/index.php" URL. An attacker could execute arbitrary HTML and script code in... Read more
Affected Products : shimmie- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6908
An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (fID) passed to the "concrete5-legacy-master/web/concrete/tools/files/selector_data.php" URL. An attacker could execute arbitrar... Read more
Affected Products : concrete5- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6907
An issue was discovered in Open.GL before 2017-03-13. The vulnerability exists due to insufficient filtration of user-supplied data (content) passed to the "Open.GL-master/index.php" URL. An attacker could execute arbitrary HTML and script code in a brows... Read more
Affected Products : open.gl- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6906
An issue was discovered in SiberianCMS before 4.10.0. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "SiberianCMS-master/errors/500.php" URL. An attacker could execute arbitrary HTML and script code in ... Read more
Affected Products : siberiancms- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6905
An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (disable_choose) passed to the "concrete5-legacy-master/web/concrete/tools/files/search_dialog.php" URL. An attacker could execu... Read more
Affected Products : concrete5- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6903
In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger l... Read more
Affected Products : ioquake3- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-3899
SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.... Read more
Affected Products : advanced_threat_defense- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025