CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-15746

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADIMAGE+0x00000000003d21b3."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15748

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADIMAGE+0x000000000000613a."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15749

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADIMAGE+0x00000000000348b9."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15751

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at BabaCAD4Image!ShowPlugInOptions+0x0000000000009f39."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15752

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000004d6b0."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15753

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at BabaCAD4Image!ShowPlugInOptions+0x00000000000029c2."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15754

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x0000000000013968."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15755

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at verifier!AVrfpDphFindBusyMemoryNoCheck+0x0000000000000091."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15758

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Image!ShowPlugInOptions+0x000000000004d75b."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15759

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001b3f3."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15760

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001ce82."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15761

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001ecaa."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15766

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at BabaCAD4Image!ShowPlugInOptions+0x000000000001f0a0."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15767

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at CADIMAGE+0x00000000003d5b52."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15768

    Last Modified: 20 Apr 2025

    IrfanView version 4.50 - 64bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file, related to "Data from Faulting Address controls Branch Selection starting at image000007f7_42060000+0x0000000000094113."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15769

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dds file, related to "Read Access Violation starting at FORMATS!ReadBLP_W+0x0000000000001b22."

    Published: 22 Oct 2017
    Unknown

    CVE-2017-15771

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15773

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285d79."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15774

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls Code Flow starting at CADImage+0x0000000000221a9a."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15775

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000259aa4."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15776

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000285ec1."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15779

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at CADImage+0x00000000000034b0."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15780

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285dad."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15781

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Read Access Violation on Control Flow starting at CADImage+0x0000000000286a76."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15782

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x00000000000032eb."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15783

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000285ce1."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15787

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation starting at xnview+0x0000000000580063."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15788

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x0000000000002d83."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15789

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x00000000000048e7."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15745

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADIMAGE+0x000000000002ca2e."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15737

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADIMAGE+0x00000000003d246f."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15743

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADIMAGE+0x00000000003d24a0."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2017-15744

    Last Modified: 20 Apr 2025

    IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Read Access Violation on Control Flow starting at CADIMAGE+0x00000000003d35a7."

    Published: 22 Oct 2017
    7.8
    High

    CVE-2018-8883

    Last Modified: 21 Nov 2024

    Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled access to nasm_reg_flags.

    Published: 22 Oct 2017
    7.5
    High

    CVE-2017-15227

    Last Modified: 20 Apr 2025

    Irssi before 1.0.5, while waiting for the channel synchronisation, may incorrectly fail to remove destroyed channels from the query list, resulting in use-after-free conditions when updating the state later on.

    Published: 22 Oct 2017
    7.5
    High

    CVE-2017-15228

    Last Modified: 20 Apr 2025

    Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.

    Published: 22 Oct 2017
    5.9
    Medium

    CVE-2017-15722

    Last Modified: 20 Apr 2025

    In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string.

    Published: 22 Oct 2017
    7.5
    High

    CVE-2017-15723

    Last Modified: 20 Apr 2025

    In Irssi before 1.0.5, overlong nicks or targets may result in a NULL pointer dereference while splitting the message.

    Published: 22 Oct 2017
    5.5
    Medium

    CVE-2017-15873

    Last Modified: 9 Jun 2025

    The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.

    Published: 22 Oct 2017
    6.6
    Medium

    CVE-2017-16646

    Last Modified: 20 Apr 2025

    drivers/media/usb/dvb-usb/dib0700_devices.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (BUG and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 22 Oct 2017
    7.5
    High

    CVE-2017-15721

    Last Modified: 20 Apr 2025

    In Irssi before 1.0.5, certain incorrectly formatted DCC CTCP messages could cause a NULL pointer dereference. This is a separate, but similar, issue relative to CVE-2017-9468.

    Published: 22 Oct 2017
    5
    Medium

    CVE-2017-15874

    Last Modified: 9 Jun 2025

    archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.

    Published: 22 Oct 2017
    8.8
    High

    CVE-2017-15731

    Last Modified: 20 Apr 2025

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.

    Published: 21 Oct 2017
    8.8
    High

    CVE-2017-15732

    Last Modified: 20 Apr 2025

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.

    Published: 21 Oct 2017
    8.8
    High

    CVE-2017-15734

    Last Modified: 20 Apr 2025

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.

    Published: 21 Oct 2017
    8.8
    High

    CVE-2017-15735

    Last Modified: 20 Apr 2025

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.

    Published: 21 Oct 2017
    8.8
    High

    CVE-2017-15733

    Last Modified: 20 Apr 2025

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php.

    Published: 21 Oct 2017
    6.7
    Medium

    CVE-2017-12317

    Last Modified: 20 Apr 2025

    The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in the local application software. The vulnerability is due to the use of a static key value stored in the application used to encrypt the connector protection password. An attacker could exploit this vulnerability by gaining local, administrative access to a Windows host and stopping the Cisco AMP for Endpoints service. Cisco Bug IDs: CSCvg42904.

    Published: 21 Oct 2017
    8.8
    High

    CVE-2017-15730

    Last Modified: 20 Apr 2025

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.

    Published: 21 Oct 2017
    8.8
    High

    CVE-2017-15729

    Last Modified: 20 Apr 2025

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary.

    Published: 21 Oct 2017