CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-5247

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadRLAImage in coders/rla.c.

    Published: 4 Jan 2018
    8.8
    High

    CVE-2018-5248

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the sixel_decode function.

    Published: 4 Jan 2018
    5.6
    Medium

    CVE-2017-5754

    Last Modified: 28 May 2026

    Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

    Published: 3 Jan 2018
    5.6
    Medium

    CVE-2017-5753

    Last Modified: 28 May 2026

    Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

    Published: 3 Jan 2018
    5.6
    Medium

    CVE-2017-5715

    Last Modified: 6 May 2025

    Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2018-5079

    Last Modified: 21 Nov 2024

    In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002130.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2018-5080

    Last Modified: 21 Nov 2024

    In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020FC.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2018-5083

    Last Modified: 21 Nov 2024

    In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300215B.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2018-5084

    Last Modified: 21 Nov 2024

    In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300212C.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2018-5085

    Last Modified: 21 Nov 2024

    In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002124.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2018-5086

    Last Modified: 21 Nov 2024

    In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300215F.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2018-5087

    Last Modified: 21 Nov 2024

    In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002100.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2018-5088

    Last Modified: 21 Nov 2024

    In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8300211C.

    Published: 3 Jan 2018
    Unknown

    CVE-2018-5191

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-1000479. Reason: This candidate is a reservation duplicate of CVE-2017-1000479. Notes: All CVE users should reference CVE-2017-1000479 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Jan 2018
    7.8
    High

    CVE-2018-5082

    Last Modified: 21 Nov 2024

    In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002128.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2018-5081

    Last Modified: 21 Nov 2024

    In K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F0.

    Published: 3 Jan 2018
    4.8
    Medium

    CVE-2018-5074

    Last Modified: 21 Nov 2024

    Online Ticket Booking has XSS via the admin/manageownerlist.php contact parameter.

    Published: 3 Jan 2018
    6.8
    Medium

    CVE-2018-5073

    Last Modified: 21 Nov 2024

    Online Ticket Booking has CSRF via admin/movieedit.php.

    Published: 3 Jan 2018
    4.8
    Medium

    CVE-2018-5072

    Last Modified: 21 Nov 2024

    Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter.

    Published: 3 Jan 2018
    4.8
    Medium

    CVE-2018-5075

    Last Modified: 21 Nov 2024

    Online Ticket Booking has XSS via the admin/snacks_edit.php snacks_name parameter.

    Published: 3 Jan 2018
    4.8
    Medium

    CVE-2018-5076

    Last Modified: 21 Nov 2024

    Online Ticket Booking has XSS via the admin/newsedit.php newstitle parameter.

    Published: 3 Jan 2018
    4.8
    Medium

    CVE-2018-5077

    Last Modified: 21 Nov 2024

    Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter.

    Published: 3 Jan 2018
    4.8
    Medium

    CVE-2018-5078

    Last Modified: 21 Nov 2024

    Online Ticket Booking has XSS via the admin/eventlist.php cast parameter.

    Published: 3 Jan 2018
    6.5
    Medium

    CVE-2017-1000460

    Last Modified: 21 Nov 2024

    In line libavcodec/h264dec.c:500 in libav(v13_dev0), ffmpeg(n3.4), chromium(56 prior Feb 13, 2017), the return value of init_get_bits is ignored and get_ue_golomb(&gb) is called on an uninitialized get_bits context, which causes a NULL deref exception.

    Published: 3 Jan 2018
    4.7
    Medium

    CVE-2017-1000461

    Last Modified: 21 Nov 2024

    Brave Software's Brave Browser, version 0.19.73 (and earlier) is vulnerable to an incorrect access control issue in the "JS fingerprinting blocking" component, resulting in a malicious website being able to access the fingerprinting-associated browser functionality (that the browser intends to block).

    Published: 3 Jan 2018
    7.5
    High

    CVE-2017-1000470

    Last Modified: 21 Nov 2024

    EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of service.

    Published: 3 Jan 2018
    6.5
    Medium

    CVE-2017-1000472

    Last Modified: 21 Nov 2024

    The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompression, and possibly create or overwrite arbitrary files, via a crafted ZIP file, related to a "file path injection vulnerability".

    Published: 3 Jan 2018
    5.4
    Medium

    CVE-2017-1000462

    Last Modified: 21 Nov 2024

    BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.

    Published: 3 Jan 2018
    9.8
    Critical

    CVE-2017-1000471

    Last Modified: 21 Nov 2024

    EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2017-1000473

    Last Modified: 21 Nov 2024

    Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are parsed and then executed resulting in code execution on the server, potentially as root.

    Published: 3 Jan 2018
    9.8
    Critical

    CVE-2017-1000486

    Last Modified: 5 Nov 2025

    Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

    Published: 3 Jan 2018
    7.8
    High

    CVE-2017-1000485

    Last Modified: 21 Nov 2024

    Nylas Mail Lives 2.2.2 uses 0755 permissions for $HOME/.nylas-mail, which allows local users to obtain sensitive authentication information via standard filesystem operations.

    Published: 3 Jan 2018
    7.5
    High

    CVE-2017-1000477

    Last Modified: 21 Nov 2024

    XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.

    Published: 3 Jan 2018
    5.4
    Medium

    CVE-2017-1000478

    Last Modified: 21 Nov 2024

    ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript and denial of service.

    Published: 3 Jan 2018
    8.8
    High

    CVE-2017-1000479

    Last Modified: 21 Nov 2024

    pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since version 16.1.16 released on June 06, 2016. The unprotected web form was removed from the code during an internal security audit under "possibly insecure" suspicions.

    Published: 3 Jan 2018
    9.8
    Critical

    CVE-2017-1000480

    Last Modified: 21 Nov 2024

    Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.

    Published: 3 Jan 2018
    6.5
    Medium

    CVE-2017-1000490

    Last Modified: 21 Nov 2024

    Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.

    Published: 3 Jan 2018
    8.1
    High

    CVE-2017-1000489

    Last Modified: 21 Nov 2024

    Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address

    Published: 3 Jan 2018
    6.1
    Medium

    CVE-2017-1000488

    Last Modified: 21 Nov 2024

    Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.

    Published: 3 Jan 2018
    Unknown

    CVE-2017-14391

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15556

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15560

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15562

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15563

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15564

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15561

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-14392

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-8026

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-8043

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    5.4
    Medium

    CVE-2017-1000467

    Last Modified: 21 Nov 2024

    LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.

    Published: 3 Jan 2018