CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-14538

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at jbig2dec+0x0000000000008823."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14545

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .epub file, related to "Data from Faulting Address controls Branch Selection starting at STDUEPubFile!DllUnregisterServer+0x0000000000010332."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14554

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to a "Possible Stack Corruption starting at STDUDjVuFile!DllUnregisterServer+0x000000000000d908."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14555

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at STDUDjVuFile!DllUnregisterServer+0x000000000000ec6e."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14569

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to a "Read Access Violation starting at STDUXPSFile!DllUnregisterServer+0x0000000000005bd5."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14575

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to an "Illegal Instruction Violation starting at Unknown Symbol @ 0x0000000002d8024c called from STDUXPSFile!DllUnregisterServer+0x000000000002566c."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14580

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.41 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at jbig2dec+0x000000000000870f."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14562

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to an "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14563

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at STDUXPSFile!DllUnregisterServer+0x0000000000005311."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14565

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to a "Possible Stack Corruption starting at Unknown Symbol @ 0x00000000038f2fbf called from image00000000_00400000+0x0000000000240065."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14553

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "User Mode Write AV starting at STDUDjVuFile!DllUnregisterServer+0x00000000000085f5."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14539

    Last Modified: 20 Apr 2025

    IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x000000000011d767."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14540

    Last Modified: 20 Apr 2025

    IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at CADIMAGE+0x000000000001f23e."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14541

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x000000000001f23e."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14542

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .epub file, related to a "Read Access Violation on Block Data Move starting at STDUEPubFile!DllUnregisterServer+0x0000000000010262."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14543

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .epub file, related to "Data from Faulting Address controls Branch Selection starting at STDUEPubFile!DllUnregisterServer+0x0000000000039335."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14544

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .epub file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at STDUEPubFile!DllUnregisterServer+0x000000000003fff1."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14546

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .epub file, related to an "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14547

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .mobi file, related to a "Read Access Violation starting at STDUMOBIFile!DllUnregisterServer+0x000000000002efc0."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14548

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "User Mode Write AV starting at STDUDjVuFile!DllUnregisterServer+0x000000000000854d."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14549

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "Heap Corruption starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14550

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to a "Possible Stack Corruption starting at STDUDjVuFile!DllUnregisterServer+0x000000000000e8b8."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14551

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address controls Branch Selection starting at STDUDjVuFile!DllUnregisterServer+0x000000000000d9f2."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14552

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "User Mode Write AV starting at STDUDjVuFile!DllUnregisterServer+0x000000000000d9a9."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14557

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "User Mode Write AV starting at STDUDjVuFile!DllUnregisterServer+0x000000000000dd3f."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14558

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "User Mode Write AV starting at STDUDjVuFile!DllUnregisterServer+0x0000000000018cc2."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14559

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at STDUXPSFile!DllUnregisterServer+0x0000000000005af2."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14560

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at STDUXPSFile!DllUnregisterServer+0x0000000000005bd2."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14561

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to an "Illegal Instruction Violation starting at Unknown Symbol @ 0x00000000048c024d called from STDUXPSFile!DllUnregisterServer+0x0000000000025638."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14564

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at STDUXPSFile!DllUnregisterServer+0x0000000000028657."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14566

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV starting at Unknown Symbol @ 0x00000000039d76c4 called from Unknown Symbol @ 0x0000000000049d2c."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14567

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to an "Illegal Instruction Violation starting at Unknown Symbol @ 0x00000000028c024d called from STDUXPSFile!DllUnregisterServer+0x000000000002e77b."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14568

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to an "Illegal Instruction Violation starting at Unknown Symbol @ 0x000000000297024c called from STDUXPSFile!DllUnregisterServer+0x0000000000025630."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14570

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64LdrpInitialize+0x00000000000008e1."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14571

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to an "Illegal Instruction Violation starting at Unknown Symbol @ 0x00000000049c024c called from STDUXPSFile!DllUnregisterServer+0x0000000000025706."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14572

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV starting at Unknown Symbol @ 0x000000000479049b called from Unknown Symbol @ 0x000000000d89645b."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14573

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to an "Illegal Instruction Violation starting at Unknown Symbol @ 0x00000000030c024c called from STDUXPSFile!DllUnregisterServer+0x000000000002566a."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14574

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV starting at Unknown Symbol @ 0x0000000004940490."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14576

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to a "Possible Stack Corruption starting at Unknown Symbol @ 0x00000000049f0281."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14577

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Control Flow starting at Unknown Symbol @ 0x0000000003aa7cef called from Unknown Symbol @ 0x0000000004aa024d."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14578

    Last Modified: 20 Apr 2025

    IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ani file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77130000!RtlpCoalesceFreeBlocks+0x00000000000004b4."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14579

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "Read Access Violation on Control Flow starting at STDUJBIG2File!DllGetClassObject+0x0000000000005b70."

    Published: 18 Sept 2017
    7.8
    High

    CVE-2017-14556

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .djvu file, related to a "User Mode Write AV starting at STDUDjVuFile!DllUnregisterServer+0x000000000000da27."

    Published: 18 Sept 2017
    5.9
    Medium

    CVE-2017-6147

    Last Modified: 20 Apr 2025

    In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.1.2-HF1 and 13.0.0, an undisclosed type of responses may cause TMM to restart, causing an interruption of service when "SSL Forward Proxy" setting is enabled in both the Client and Server SSL profiles assigned to a BIG-IP Virtual Server.

    Published: 18 Sept 2017
    0
    Low

    CVE-2020-14353

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-18270. Reason: This candidate is a duplicate of CVE-2017-18270. Notes: All CVE users should reference CVE-2017-18270 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Sept 2017
    5.9
    Medium

    CVE-2017-0380

    Last Modified: 20 Apr 2025

    The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitialized stack data is included in an error message about construction of an introduction point circuit.

    Published: 18 Sept 2017
    8.8
    High

    CVE-2014-6106

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1, 6.0, and 7.0 allows remote attackers to hijack the authentication of users for requests that can cause cross-site scripting attacks, web cache poisoning, or other unspecified impacts via unknown vectors.

    Published: 18 Sept 2017
    6.1
    Medium

    CVE-2017-12156

    Last Modified: 20 Apr 2025

    Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

    Published: 18 Sept 2017
    4.3
    Medium

    CVE-2017-12157

    Last Modified: 20 Apr 2025

    In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

    Published: 18 Sept 2017
    6.1
    Medium

    CVE-2017-14534

    Last Modified: 20 Apr 2025

    Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to location.php, related to PHP_SELF.

    Published: 18 Sept 2017