CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2017-18230

    Last Modified: 21 Nov 2024

    An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 25 Sept 2017
    6.5
    Medium

    CVE-2017-18231

    Last Modified: 21 Nov 2024

    An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadEnhMetaFile in coders/emf.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 25 Sept 2017
    7.5
    High

    CVE-2017-14739

    Last Modified: 20 Apr 2025

    The AcquireResampleFilterThreadSet function in magick/resample-private.h in ImageMagick 7.0.7-4 mishandles failed memory allocation, which allows remote attackers to cause a denial of service (NULL Pointer Dereference in DistortImage in MagickCore/distort.c, and application crash) via unspecified vectors.

    Published: 25 Sept 2017
    5.5
    Medium

    CVE-2017-14932

    Last Modified: 20 Apr 2025

    decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file.

    Published: 25 Sept 2017
    7.8
    High

    CVE-2017-15020

    Last Modified: 20 Apr 2025

    dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles pointers, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file, related to parse_die and parse_line_table, as demonstrated by a parse_die heap-based buffer over-read.

    Published: 25 Sept 2017
    5.5
    Medium

    CVE-2017-15939

    Last Modified: 20 Apr 2025

    dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. NOTE: this issue is caused by an incomplete fix for CVE-2017-15023.

    Published: 25 Sept 2017
    6.5
    Medium

    CVE-2017-14989

    Last Modified: 20 Apr 2025

    A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the application via a crafted font file, because the FT_Done_Glyph function (from FreeType 2) is called at an incorrect place in the ImageMagick code.

    Published: 25 Sept 2017
    9.8
    Critical

    CVE-2017-7550

    Last Modified: 20 Apr 2025

    A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords to be specified in the "params" argument, and noting this in the module documentation.

    Published: 25 Sept 2017
    5.5
    Medium

    CVE-2017-14857

    Last Modified: 20 Apr 2025

    In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a denial of service attack.

    Published: 25 Sept 2017
    7.5
    High

    CVE-2017-14929

    Last Modified: 20 Apr 2025

    In Poppler 0.59.0, memory corruption occurs in a call to Object::dictLookup() in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opFill, Gfx::doPatternFill, Gfx::doTilingPatternFill and Gfx::drawForm calls (aka a Gfx.cc infinite loop), a different vulnerability than CVE-2017-14519.

    Published: 25 Sept 2017
    5.9
    Medium

    CVE-2017-14955

    Last Modified: 20 Apr 2025

    Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

    Published: 25 Sept 2017
    5.5
    Medium

    CVE-2017-15023

    Last Modified: 20 Apr 2025

    read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.

    Published: 25 Sept 2017
    5.5
    Medium

    CVE-2017-15022

    Last Modified: 20 Apr 2025

    dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the DW_AT_name data type, which allows remote attackers to cause a denial of service (bfd_hash_hash NULL pointer dereference, or out-of-bounds access, and application crash) via a crafted ELF file, related to scan_unit_for_symbols and parse_comp_unit.

    Published: 25 Sept 2017
    5.5
    Medium

    CVE-2017-15021

    Last Modified: 20 Apr 2025

    bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to bfd_getl32.

    Published: 24 Sept 2017
    7.5
    High

    CVE-2017-14719

    Last Modified: 20 Apr 2025

    Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.

    Published: 23 Sept 2017
    6.1
    Medium

    CVE-2017-14720

    Last Modified: 20 Apr 2025

    Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template name.

    Published: 23 Sept 2017
    7.5
    High

    CVE-2017-14722

    Last Modified: 20 Apr 2025

    Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.

    Published: 23 Sept 2017
    9.8
    Critical

    CVE-2017-14723

    Last Modified: 20 Apr 2025

    Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus did not properly address the possibility of plugins and themes enabling SQL injection attacks.

    Published: 23 Sept 2017
    6.1
    Medium

    CVE-2017-14721

    Last Modified: 20 Apr 2025

    Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.

    Published: 23 Sept 2017
    7.8
    High

    CVE-2017-14627

    Last Modified: 20 Apr 2025

    Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the TEXT tag) parameter in an lpp project file.

    Published: 23 Sept 2017
    6.1
    Medium

    CVE-2017-14718

    Last Modified: 20 Apr 2025

    Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or data: URL.

    Published: 23 Sept 2017
    5.4
    Medium

    CVE-2017-14725

    Last Modified: 20 Apr 2025

    Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

    Published: 23 Sept 2017
    6.1
    Medium

    CVE-2017-14726

    Last Modified: 20 Apr 2025

    Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual editor.

    Published: 23 Sept 2017
    7.5
    High

    CVE-2017-14727

    Last Modified: 20 Apr 2025

    logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.

    Published: 23 Sept 2017
    6.1
    Medium

    CVE-2017-14724

    Last Modified: 20 Apr 2025

    Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery.

    Published: 23 Sept 2017
    5.5
    Medium

    CVE-2017-14858

    Last Modified: 20 Apr 2025

    There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

    Published: 23 Sept 2017
    5.5
    Medium

    CVE-2017-14865

    Last Modified: 20 Apr 2025

    There is a heap-based buffer overflow in the Exiv2::us2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

    Published: 23 Sept 2017
    5.5
    Medium

    CVE-2017-14860

    Last Modified: 20 Apr 2025

    There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

    Published: 23 Sept 2017
    5.5
    Medium

    CVE-2017-14861

    Last Modified: 20 Apr 2025

    There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.

    Published: 23 Sept 2017
    5.5
    Medium

    CVE-2017-14862

    Last Modified: 20 Apr 2025

    An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

    Published: 23 Sept 2017
    5.5
    Medium

    CVE-2017-14866

    Last Modified: 20 Apr 2025

    There is a heap-based buffer overflow in the Exiv2::s2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

    Published: 23 Sept 2017
    5.5
    Medium

    CVE-2017-14930

    Last Modified: 20 Apr 2025

    Memory leak in decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.

    Published: 23 Sept 2017
    5.5
    Medium

    CVE-2017-14859

    Last Modified: 20 Apr 2025

    An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

    Published: 23 Sept 2017
    7.8
    High

    CVE-2017-14694

    Last Modified: 20 Apr 2025

    Foxit Reader 8.3.2.25013 and earlier and Foxit PhantomPDF 8.3.2.25013 and earlier, when running in single instance mode, allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at tiptsf!CPenInputPanel::FinalRelease+0x000000000000002f.".

    Published: 22 Sept 2017
    5.4
    Medium

    CVE-2017-14712

    Last Modified: 20 Apr 2025

    In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.

    Published: 22 Sept 2017
    5.4
    Medium

    CVE-2017-14713

    Last Modified: 20 Apr 2025

    In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter.

    Published: 22 Sept 2017
    5.4
    Medium

    CVE-2017-14714

    Last Modified: 20 Apr 2025

    In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter.

    Published: 22 Sept 2017
    5.4
    Medium

    CVE-2017-14715

    Last Modified: 20 Apr 2025

    In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.

    Published: 22 Sept 2017
    5.4
    Medium

    CVE-2017-14716

    Last Modified: 20 Apr 2025

    In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.

    Published: 22 Sept 2017
    5.4
    Medium

    CVE-2017-14717

    Last Modified: 20 Apr 2025

    In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.

    Published: 22 Sept 2017
    8.1
    High

    CVE-2017-14705

    Last Modified: 20 Apr 2025

    DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type parameter to the tailDateFile function in /webservices/stream/tail.php. An iToken authentication parameter is required but can be obtained by exploiting CVE-2017-14706. This affects DenyAll i-Suite LTS 5.5.0 through 5.5.12, i-Suite 5.6, Web Application Firewall 5.7, and Web Application Firewall 6.x before 6.4.1, with On Premises or AWS/Azure cloud deployments.

    Published: 22 Sept 2017
    9.8
    Critical

    CVE-2017-14706

    Last Modified: 20 Apr 2025

    DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf=debug request to /webservices/download/index.php, and then reading the iToken field in the reply. This affects DenyAll i-Suite LTS 5.5.0 through 5.5.12, i-Suite 5.6, Web Application Firewall 5.7, and Web Application Firewall 6.x before 6.4.1, with On Premises or AWS/Azure cloud deployments.

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-6268

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or possible escalation of privileges.

    Published: 22 Sept 2017
    5.5
    Medium

    CVE-2017-6266

    Last Modified: 20 Apr 2025

    NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where improper access controls could allow unprivileged users to cause a denial of service.

    Published: 22 Sept 2017
    5.5
    Medium

    CVE-2017-6267

    Last Modified: 20 Apr 2025

    NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect initialization of internal objects can cause an infinite loop which may lead to a denial of service.

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-6269

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from a user to the driver is used without validation which may lead to denial of service or possible escalation of privileges.

    Published: 22 Sept 2017
    5.5
    Medium

    CVE-2017-6270

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiCreateAllocation where untrusted user input is used as a divisor without validation during a calculation which may lead to a potential divide by zero and denial of service.

    Published: 22 Sept 2017
    5.5
    Medium

    CVE-2017-6271

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiCreateAllocation where untrusted user input is used as a divisor without validation while processing block linear information which may lead to a potential divide by zero and denial of service.

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-6272

    Last Modified: 20 Apr 2025

    NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to a denial of service or possible escalation of privileges.

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-6277

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or possible escalation of privileges.

    Published: 22 Sept 2017