CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2016-6168

    Last Modified: 21 Nov 2024

    Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a crafted PDF file.

    Published: 7 Feb 2018
    7.8
    High

    CVE-2017-12412

    Last Modified: 21 Nov 2024

    ccn-lite-ccnb2xml in CCN-lite before 2.0.0 allows context-dependent attackers to have unspecified impact via a crafted file, which triggers infinite recursion and a stack overflow.

    Published: 7 Feb 2018
    7.5
    High

    CVE-2017-12464

    Last Modified: 21 Nov 2024

    ccn-lite-valid.c in CCN-lite before 2.00 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via vectors involving the keyfile variable.

    Published: 7 Feb 2018
    9.8
    Critical

    CVE-2017-12465

    Last Modified: 21 Nov 2024

    Multiple integer overflows in CCN-lite before 2.00 allow context-dependent attackers to have unspecified impact via vectors involving the (1) vallen variable in the iottlv_parse_sequence function or (2) typ, vallen and i variables in the localrpc_parse function.

    Published: 7 Feb 2018
    9.8
    Critical

    CVE-2017-12466

    Last Modified: 21 Nov 2024

    CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors related to ssl_halen when running ccn-lite-sim, which trigger an out-of-bounds access.

    Published: 7 Feb 2018
    7.5
    High

    CVE-2017-12467

    Last Modified: 21 Nov 2024

    Memory leak in CCN-lite before 2.00 allows context-dependent attackers to cause a denial of service (memory consumption) by leveraging failure to allocate memory for the comp or complen structure member.

    Published: 7 Feb 2018
    9.8
    Critical

    CVE-2017-12468

    Last Modified: 21 Nov 2024

    Buffer overflow in ccn-lite-ccnb2xml.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors involving the vallen and len variables.

    Published: 7 Feb 2018
    9.8
    Critical

    CVE-2017-12469

    Last Modified: 21 Nov 2024

    Buffer overflow in util/ccnl-common.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging incorrect memory allocation.

    Published: 7 Feb 2018
    9.8
    Critical

    CVE-2017-12472

    Last Modified: 21 Nov 2024

    ccnl-ext-mgmt.c in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging missing NULL pointer checks after ccnl_malloc.

    Published: 7 Feb 2018
    7.5
    High

    CVE-2017-12473

    Last Modified: 21 Nov 2024

    ccnl_ccntlv_bytes2pkt in CCN-lite allows context-dependent attackers to cause a denial of service (application crash) via vectors involving packets with "wrong L values."

    Published: 7 Feb 2018
    7.8
    High

    CVE-2017-1692

    Last Modified: 21 Nov 2024

    IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM X-Force ID: 134067.

    Published: 7 Feb 2018
    9.8
    Critical

    CVE-2018-6823

    Last Modified: 21 Nov 2024

    In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implements an unprotected XPC service that can be abused to execute scripts as root.

    Published: 7 Feb 2018
    7.8
    High

    CVE-2017-17482

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow allowing a local privilege escalation when a non-privileged account enters a crafted command line. This bug is exploitable on VAX and Alpha and may cause a process crash on IA64. Software was affected regardless of whether it was directly shipped by VMS Software, Inc. (VSI), HPE, HP, Compaq, or Digital Equipment Corporation.

    Published: 7 Feb 2018
    9.8
    Critical

    CVE-2018-6822

    Last Modified: 21 Nov 2024

    In PureVPN 6.0.1 on macOS, HelperTool LaunchDaemon implements an unprotected XPC service that can be abused to execute system commands as root.

    Published: 7 Feb 2018
    6.1
    Medium

    CVE-2018-6603

    Last Modified: 21 Nov 2024

    Promise Technology WebPam Pro-E devices allow remote attackers to conduct XSS, HTTP Response Splitting, and CRLF Injection attacks via JavaScript code in a PHPSESSID cookie.

    Published: 7 Feb 2018
    5.3
    Medium

    CVE-2018-6794

    Last Modified: 21 Nov 2024

    Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a normal TCP flow and sends data before the 3-way handshake is complete, then the data sent by the malicious server will be accepted by web clients such as a web browser or Linux CLI utilities, but ignored by Suricata IDS signatures. This mostly affects IDS signatures for the HTTP protocol and TCP stream content; signatures for TCP packets will inspect such network traffic as usual.

    Published: 7 Feb 2018
    8.8
    High

    CVE-2018-6799

    Last Modified: 21 Nov 2024

    The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used.

    Published: 7 Feb 2018
    6.5
    Medium

    CVE-2018-6806

    Last Modified: 21 Nov 2024

    Marked 2 through 2.5.11 allows remote attackers to read arbitrary files via a crafted HTML document that triggers a redirect to an x-marked://preview?text= URL. The value of the text parameter can include arbitrary JavaScript code, e.g., making XMLHttpRequest calls.

    Published: 7 Feb 2018
    6.8
    Medium

    CVE-2018-6791

    Last Modified: 21 Nov 2024

    An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.

    Published: 7 Feb 2018
    5.3
    Medium

    CVE-2018-6790

    Last Modified: 21 Nov 2024

    An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.

    Published: 7 Feb 2018
    8.8
    High

    CVE-2018-6792

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in Saifor CVMS HUB 1.3.1 allow an authenticated user to execute arbitrary SQL commands via multiple parameters to the /cvms-hub/privado/seccionesmib/secciones.xhtml resource. The POST parameters are j_idt118, j_idt120, j_idt122, j_idt124, j_idt126, j_idt128, and j_idt130 under formularioGestionarSecciones:tablaSeccionesMib:*:filter. The GET parameter is nombreAgente.

    Published: 7 Feb 2018
    5.5
    Medium

    CVE-2018-8945

    Last Modified: 21 Nov 2024

    The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (segmentation fault) via a large attribute section.

    Published: 7 Feb 2018
    7.8
    High

    CVE-2018-6574

    Last Modified: 21 Nov 2024

    Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.

    Published: 7 Feb 2018
    7.8
    High

    CVE-2018-1000032

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.

    Published: 7 Feb 2018
    9.1
    Critical

    CVE-2018-1000034

    Last Modified: 21 Nov 2024

    An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.

    Published: 7 Feb 2018
    7.8
    High

    CVE-2018-1000035

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow exists in Info-Zip UnZip version <= 6.00 in the processing of password-protected archives that allows an attacker to perform a denial of service or to possibly achieve code execution.

    Published: 7 Feb 2018
    9.1
    Critical

    CVE-2018-1000033

    Last Modified: 21 Nov 2024

    An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.

    Published: 7 Feb 2018
    9.8
    Critical

    CVE-2018-6789

    Last Modified: 7 Nov 2025

    An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.

    Published: 7 Feb 2018
    6.5
    Medium

    CVE-2018-6876

    Last Modified: 21 Nov 2024

    The OLEProperty class in ole/oleprop.cpp in libfpx 1.3.1-10, as used in ImageMagick 7.0.7-22 Q16 and other products, allows remote attackers to cause a denial of service (stack-based buffer under-read) via a crafted bmp image.

    Published: 7 Feb 2018
    6.5
    Medium

    CVE-2018-7725

    Last Modified: 10 Jul 2025

    An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial of service.

    Published: 7 Feb 2018
    7.8
    High

    CVE-2018-1000031

    Last Modified: 21 Nov 2024

    A heap-based buffer overflow exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service or to possibly achieve code execution.

    Published: 7 Feb 2018
    7.8
    High

    CVE-2018-6769

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x99008020.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6770

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x99008210.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6771

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x99008224.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6772

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x99008208.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6773

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008084.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6775

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x990081C8.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6776

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A00813C.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6777

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220400.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6778

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008268.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6779

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008240.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6780

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A0081E4.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6782

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A0081DC.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6783

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A00825C.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6784

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A00824C.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6785

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008254.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6788

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x2208C0.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6786

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x220840.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6768

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008090.

    Published: 6 Feb 2018
    7.8
    High

    CVE-2018-6774

    Last Modified: 21 Nov 2024

    In Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9A008088.

    Published: 6 Feb 2018