CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-17912

    Last Modified: 20 Apr 2025

    In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region.

    Published: 26 Dec 2017
    8.8
    High

    CVE-2017-17915

    Last Modified: 20 Apr 2025

    In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached.

    Published: 26 Dec 2017
    6.1
    Medium

    CVE-2017-17911

    Last Modified: 20 Apr 2025

    packages/core/contact.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?p=core/contact request, aka Open Bug Bounty ID OBB-278503.

    Published: 26 Dec 2017
    9.8
    Critical

    CVE-2017-17875

    Last Modified: 20 Apr 2025

    The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.

    Published: 26 Dec 2017
    7.5
    High

    CVE-2017-17876

    Last Modified: 20 Apr 2025

    Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a user=download request with a pathname in the path parameter.

    Published: 26 Dec 2017
    9.8
    Critical

    CVE-2017-9944

    Last Modified: 20 Apr 2025

    A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to perform administrative operations over the network.

    Published: 26 Dec 2017
    5.9
    Medium

    CVE-2017-12740

    Last Modified: 20 Apr 2025

    Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to manipulate the software package while performing a Man-in-the-Middle (MitM) attack.

    Published: 26 Dec 2017
    8.8
    High

    CVE-2017-12736

    Last Modified: 12 Aug 2025

    After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow an attacker located in the adjacent network of the targeted device to perform unauthorized administrative actions.

    Published: 26 Dec 2017
    8.7
    High

    CVE-2017-12741

    Last Modified: 20 Apr 2025

    Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.

    Published: 26 Dec 2017
    6.5
    Medium

    CVE-2017-17934

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.7-17 Q16 x86_64 has memory leaks in coders/msl.c, related to MSLPopImage and ProcessMSLScript, and associated with mishandling of MSLPushImage calls.

    Published: 26 Dec 2017
    7.8
    High

    CVE-2017-13848

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 25 Dec 2017
    5.9
    Medium

    CVE-2017-13860

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "Mail Drafts" component. It allows man-in-the-middle attackers to read e-mail content by leveraging mishandling of S/MIME credential encryption.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-13862

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-13867

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-13875

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via a crafted app.

    Published: 25 Dec 2017
    7.5
    High

    CVE-2017-13903

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2.1 is affected. tvOS before 11.2.1 is affected. The issue involves the "HomeKit" component. It allows remote attackers to modify the application state by leveraging incorrect message handling, as demonstrated by use of an Apple Watch to obtain an encryption key and unlock a door.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-13861

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOSurface" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-7162

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-13847

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    5.5
    Medium

    CVE-2017-13855

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app that triggers type confusion.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-13858

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 25 Dec 2017
    5.9
    Medium

    CVE-2017-13864

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. The issue involves the "APNs Server" component. It allows man-in-the-middle attackers to track users by leveraging mishandling of client certificates.

    Published: 25 Dec 2017
    5.5
    Medium

    CVE-2017-13865

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 25 Dec 2017
    5.5
    Medium

    CVE-2017-13869

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 25 Dec 2017
    7.5
    High

    CVE-2017-13871

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Mail" component. It allows remote attackers to read cleartext e-mail content (for which S/MIME encryption was intended) by leveraging the lack of installation of an S/MIME certificate by the recipient.

    Published: 25 Dec 2017
    7.5
    High

    CVE-2017-13874

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. The issue involves the "Mail" component. It might allow remote attackers to bypass an intended encryption protection mechanism by leveraging incorrect S/MIME certificate selection.

    Published: 25 Dec 2017
    7.1
    High

    CVE-2017-13878

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (out-of-bounds read and system crash).

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-13879

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. The issue involves the "IOMobileFrameBuffer" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-13883

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    4.3
    Medium

    CVE-2017-7152

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. The issue involves the "Mail Message Framework" component. It allows remote attackers to spoof the address bar via a crafted web site.

    Published: 25 Dec 2017
    6.6
    Medium

    CVE-2017-7154

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (system crash).

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-7155

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    6.5
    Medium

    CVE-2017-7158

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Screen Sharing Server" component. It allows attackers to obtain root privileges for reading files by leveraging screen-sharing access.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-7159

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "IOAcceleratorFamily" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    5.5
    Medium

    CVE-2017-13868

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-13876

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    8.8
    High

    CVE-2017-7160

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 25 Dec 2017
    7.8
    High

    CVE-2017-7163

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Dec 2017
    6.1
    Medium

    CVE-2017-17907

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename parameter.

    Published: 25 Dec 2017
    8.8
    High

    CVE-2017-17908

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.

    Published: 25 Dec 2017
    4.8
    Medium

    CVE-2017-17909

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.

    Published: 25 Dec 2017
    8.8
    High

    CVE-2017-17903

    Last Modified: 20 Apr 2025

    FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.

    Published: 25 Dec 2017
    5.4
    Medium

    CVE-2017-17904

    Last Modified: 20 Apr 2025

    FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile.

    Published: 25 Dec 2017
    8.8
    High

    CVE-2017-17905

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php.

    Published: 25 Dec 2017
    9.8
    Critical

    CVE-2017-17906

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.

    Published: 25 Dec 2017
    6
    Medium

    CVE-2018-5683

    Last Modified: 21 Nov 2024

    The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by leveraging improper memory address validation.

    Published: 25 Dec 2017
    6.5
    Medium

    CVE-2017-18272

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-25, there is a use-after-free in ReadOneMNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted MNG image file that is mishandled in an MngInfoDiscardObject call.

    Published: 25 Dec 2017
    9.8
    Critical

    CVE-2017-17892

    Last Modified: 20 Apr 2025

    Readymade Video Sharing Script has SQL Injection via the viewsubs.php chnlid parameter or the search_video.php search parameter.

    Published: 24 Dec 2017
    6.1
    Medium

    CVE-2017-17893

    Last Modified: 20 Apr 2025

    Readymade Video Sharing Script has XSS via the search_video.php search parameter, the viewsubs.php chnlid parameter, or the user-profile-edit.php fname parameter.

    Published: 24 Dec 2017
    9.8
    Critical

    CVE-2017-17900

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.

    Published: 24 Dec 2017