Latest CVE Feed
-
9.3
HIGHCVE-2017-3003
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to an interaction between the privacy user interface and the ActionScript 2 Camera object. Successful exploitation could lead to arbitrary code exe... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-3002
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability in the ActionScript2 TextField object related to the variable property. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-3001
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to garbage collection in the ActionScript 2 VM. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-3000
Adobe Flash Player versions 24.0.0.221 and earlier have a vulnerability in the random number generator used for constant blinding. Successful exploitation could lead to information disclosure.... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2999
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK functionality related to hosting playback surface. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2998
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK API functionality related to timeline interactions. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2997
Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable buffer overflow / underflow vulnerability in the Primetime TVSDK that supports customizing ad information. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2983
Adobe Shockwave versions 12.2.7.197 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to escalation of privilege.... Read more
Affected Products : shockwave_player- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6335
The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a small samples per pixel value in a CMYKA TIFF file.... Read more
Affected Products : graphicsmagick- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-5957
Stack-based buffer overflow in the vrend_decode_set_framebuffer_state function in vrend_decode.c in virglrenderer before 926b9b3460a48f6454d8bbe9e44313d86a65447f, as used in Quick Emulator (QEMU), allows a local guest users to cause a denial of service (a... Read more
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5668
bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list. NOTE: this vulnerabili... Read more
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10189
BitlBee before 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list.... Read more
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10188
Use-after-free vulnerability in bitlbee-libpurple before 3.5 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code by causing a file transfer connection to expire.... Read more
Affected Products : bitlbee- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10172
The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.... Read more
Affected Products : wavpack- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10171
The unreorder_channels function in cli/wvunpack.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.... Read more
Affected Products : wavpack- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10170
The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.... Read more
Affected Products : wavpack- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10169
The read_code function in read_words.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.... Read more
Affected Products : wavpack- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-6883
The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vuln... Read more
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6877
Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim 0.7.1 and earlier allows remote attackers to inject arbitrary web script.... Read more
Affected Products : lutim- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-6874
Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behav... Read more
Affected Products : linux_kernel- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025