CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2017-13821

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFString" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13822

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Quick Look" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13823

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "QuickTime" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13825

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a crafted font file.

    Published: 13 Nov 2017
    Unknown

    CVE-2017-13826

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-10140. Reason: This candidate is a reservation duplicate of CVE-2017-10140. Notes: All CVE users should reference CVE-2017-10140 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13828

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Fonts" component. It allows remote attackers to spoof the user interface via crafted text.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13829

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFNetwork" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13830

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "HFS" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 13 Nov 2017
    7.1
    High

    CVE-2017-13831

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to obtain sensitive information or cause a denial of service via a crafted image.

    Published: 13 Nov 2017
    9.8
    Critical

    CVE-2017-13832

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "802.1X" component. It allows attackers to have an unspecified impact by leveraging TLS 1.0 support.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13833

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFNetwork" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13836

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13840

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13841

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-7113

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "UIKit" component. It allows attackers to bypass intended read restrictions for secure text fields via vectors involving a focus-change event.

    Published: 13 Nov 2017
    2.4
    Low

    CVE-2017-13844

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "Messages" component. It allows physically proximate attackers to view arbitrary photos via a Reply With Message action in the lock-screen state.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13783

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13784

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13788

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    6.5
    Medium

    CVE-2017-13789

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13791

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13794

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13802

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13803

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    2.4
    Low

    CVE-2017-13805

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to obtain sensitive information via a Siri request for private-content notifications that should not have been available in the lock-screen state.

    Published: 13 Nov 2017
    7.1
    High

    CVE-2017-13820

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ATS" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted font.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13824

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Open Scripting Architecture" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted AppleScript file that is mishandled by osadecompile.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13838

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Sandbox" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-7132

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Quick Look" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a crafted Office document.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-16808

    Last Modified: 20 Apr 2025

    tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c.

    Published: 13 Nov 2017
    7.2
    High

    CVE-2017-15113

    Last Modified: 21 Nov 2024

    ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-level logs are shared with vendors or other parties to troubleshoot issues.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13782

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a /dev/dtracehelper attack involving the dtrace_dif_variable and dtrace_getarg functions.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-15288

    Last Modified: 20 Apr 2025

    The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-16837

    Last Modified: 20 Apr 2025

    Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users to overwrite dynamic PCRs of Trusted Platform Module (TPM) by hooking these function pointers.

    Published: 13 Nov 2017
    8.1
    High

    CVE-2017-16853

    Last Modified: 20 Apr 2025

    The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka CPPOST-105.

    Published: 13 Nov 2017
    5.4
    Medium

    CVE-2017-16798

    Last Modified: 20 Apr 2025

    In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS via other extensions, as demonstrated by .phtml, .pht, .html, or .svg.

    Published: 12 Nov 2017
    7.8
    High

    CVE-2017-16796

    Last Modified: 20 Apr 2025

    In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows remote attackers to cause a denial of service (invalid write and application crash) or possibly have unspecified other impact via vectors involving an IDAT tag in a crafted PNG file.

    Published: 12 Nov 2017
    5.4
    Medium

    CVE-2017-16799

    Last Modified: 20 Apr 2025

    In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to admin/moduleinterface.php during addition of a category, a related issue to CVE-2010-3882.

    Published: 12 Nov 2017
    7.8
    High

    CVE-2017-16797

    Last Modified: 20 Apr 2025

    In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an alloclen_64 multiplication of width and height values, which allows remote attackers to cause a denial of service (integer overflow, heap-based buffer overflow, and application crash) or possibly have unspecified other impact via a crafted PNG file.

    Published: 12 Nov 2017
    7.8
    High

    CVE-2017-16793

    Last Modified: 20 Apr 2025

    The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote attackers to cause a denial of service (incorrect malloc and heap-based buffer overflow) or possibly have unspecified other impact via a crafted file.

    Published: 12 Nov 2017
    5.5
    Medium

    CVE-2017-16794

    Last Modified: 20 Apr 2025

    The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as demonstrated by an erroneous png_load call that occurs because of incorrect integer data types in png2swf.

    Published: 12 Nov 2017
    5.5
    Medium

    CVE-2017-17080

    Last Modified: 20 Apr 2025

    elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which allows remote attackers to cause a denial of service (bfd_getl32 heap-based buffer over-read and application crash) via a crafted object file, related to elfcore_grok_netbsd_procinfo, elfcore_grok_openbsd_procinfo, and elfcore_grok_nto_status.

    Published: 11 Nov 2017
    7.5
    High

    CVE-2017-16520

    Last Modified: 20 Apr 2025

    Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.

    Published: 11 Nov 2017
    9.8
    Critical

    CVE-2017-16783

    Last Modified: 20 Apr 2025

    In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.

    Published: 10 Nov 2017
    9.8
    Critical

    CVE-2017-16780

    Last Modified: 20 Apr 2025

    The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.

    Published: 10 Nov 2017
    5.4
    Medium

    CVE-2017-16781

    Last Modified: 20 Apr 2025

    The installer in MyBB before 1.8.13 has XSS.

    Published: 10 Nov 2017
    6.1
    Medium

    CVE-2017-16782

    Last Modified: 20 Apr 2025

    In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.

    Published: 10 Nov 2017
    6.1
    Medium

    CVE-2017-16785

    Last Modified: 20 Apr 2025

    Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.

    Published: 10 Nov 2017
    6.1
    Medium

    CVE-2017-16784

    Last Modified: 20 Apr 2025

    In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.

    Published: 10 Nov 2017
    6.1
    Medium

    CVE-2017-16765

    Last Modified: 20 Apr 2025

    XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.

    Published: 10 Nov 2017