Latest CVE Feed
-
5.9
MEDIUMCVE-2016-9892
The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6104
Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.... Read more
Affected Products : zen_mobile_app_native- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6103
Persistent XSS Vulnerability in Wordpress plugin AnyVar v0.1.1.... Read more
Affected Products : anyvar- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6102
Persistent XSS in wordpress plugin rockhoist-badges v1.2.2.... Read more
Affected Products : rockhoist_badges_plugin- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10071
coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.... Read more
Affected Products : imagemagick- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10069
coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames.... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10068
The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10067
magick/memory.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via vectors involving "too many exceptions," which trigger a buffer overflow.... Read more
Affected Products : imagemagick- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10064
Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10063
Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file, related to extend validity.... Read more
Affected Products : imagemagick- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10062
The ReadGROUP4Image function in coders/tiff.c in ImageMagick does not check the return value of the fwrite function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.... Read more
Affected Products : imagemagick- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-10060
The ConcatenateImages function in MagickWand/magick-cli.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.... Read more
Affected Products : imagemagick- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5235
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.... Read more
Affected Products : metasploit- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5234
Rapid7 Insight Collector installers prior to version 1.0.16 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.... Read more
Affected Products : insight_collector- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5233
Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.... Read more
Affected Products : appspider_pro- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5232
All editions of Rapid7 Nexpose installers prior to version 6.4.24 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.... Read more
Affected Products : nexpose- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-5231
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to writ... Read more
Affected Products : metasploit- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-5230
The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not modifiable by the user. The keystore provides storage for saved scan credentials in an otherwise secure l... Read more
Affected Products : nexpose- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-5229
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an ar... Read more
Affected Products : metasploit- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-5228
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary ... Read more
Affected Products : metasploit- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025