CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2017-5109

    Last Modified: 20 Apr 2025

    Inappropriate implementation of unload handler handling in permission prompts in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-12671

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-3, a missing NULL assignment was found in coders/png.c, leading to an invalid free in the function RelinquishMagickMemory in MagickCore/memory.c, which allows attackers to cause a denial of service.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-5091

    Last Modified: 20 Apr 2025

    A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-5098

    Last Modified: 20 Apr 2025

    A use after free in V8 in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-5108

    Last Modified: 20 Apr 2025

    Type confusion in PDFium in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted PDF file.

    Published: 25 Jul 2017
    5.5
    Medium

    CVE-2017-11625

    Last Modified: 20 Apr 2025

    A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDF::resolveObjectsInStream function in QPDF.cc, aka an "infinite loop."

    Published: 25 Jul 2017
    5.5
    Medium

    CVE-2017-11626

    Last Modified: 20 Apr 2025

    A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after four consecutive calls to QPDFObjectHandle::parseInternal, aka an "infinite loop."

    Published: 25 Jul 2017
    5.5
    Medium

    CVE-2017-11627

    Last Modified: 20 Apr 2025

    A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the PointerHolder function in PointerHolder.hh, aka an "infinite loop."

    Published: 25 Jul 2017
    7.8
    High

    CVE-2017-11628

    Last Modified: 20 Apr 2025

    In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, a stack-based buffer overflow in the zend_ini_do_op() function in Zend/zend_ini_parser.c could cause a denial of service or potentially allow executing code. NOTE: this is only relevant for PHP applications that accept untrusted input (instead of the system's php.ini file) for the parse_ini_string or parse_ini_file function, e.g., a web application for syntax validation of php.ini directives.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-12672

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-12673

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function ReadOneMNGImage in coders/png.c, which allows attackers to cause a denial of service.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-12675

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-3, a missing check for multidimensional data was found in coders/mat.c, leading to a memory leak in the function ReadImage in MagickCore/constitute.c, which allows attackers to cause a denial of service.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-12676

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function ReadOneJNGImage in coders/png.c, which allows attackers to cause a denial of service.

    Published: 25 Jul 2017
    5.5
    Medium

    CVE-2017-18237

    Last Modified: 21 Nov 2024

    An issue was discovered in Exempi before 2.4.3. The PostScript_Support::ConvertToDate function in XMPFiles/source/FormatSupport/PostScript_Support.cpp allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via a crafted .ps file.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-5097

    Last Modified: 20 Apr 2025

    Insufficient validation of untrusted input in Skia in Google Chrome prior to 60.0.3112.78 for Linux allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-5094

    Last Modified: 20 Apr 2025

    Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to potentially maliciously modify objects via a crafted HTML page.

    Published: 25 Jul 2017
    4.3
    Medium

    CVE-2017-5096

    Last Modified: 20 Apr 2025

    Insufficient policy enforcement during navigation between different schemes in Google Chrome prior to 60.0.3112.78 for Android allowed a remote attacker to perform cross origin content download via a crafted HTML page, related to intents.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-5101

    Last Modified: 20 Apr 2025

    Inappropriate implementation in Omnibox in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-5105

    Last Modified: 20 Apr 2025

    Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-5106

    Last Modified: 20 Apr 2025

    Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

    Published: 25 Jul 2017
    5.3
    Medium

    CVE-2017-5107

    Last Modified: 20 Apr 2025

    A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-5110

    Last Modified: 20 Apr 2025

    Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to spoof the contents of the Omnibox via a crafted HTML page.

    Published: 25 Jul 2017
    5.4
    Medium

    CVE-2017-7513

    Last Modified: 21 Nov 2024

    It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.

    Published: 25 Jul 2017
    7.5
    High

    CVE-2017-16932

    Last Modified: 22 Jan 2026

    parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.

    Published: 25 Jul 2017
    8.1
    High

    CVE-2016-6328

    Last Modified: 21 Nov 2024

    A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data).

    Published: 25 Jul 2017
    5.5
    Medium

    CVE-2017-11624

    Last Modified: 20 Apr 2025

    A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after two consecutive calls to QPDFObjectHandle::parseInternal, aka an "infinite loop."

    Published: 25 Jul 2017
    5.5
    Medium

    CVE-2017-18235

    Last Modified: 21 Nov 2024

    An issue was discovered in Exempi before 2.4.3. The VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp does not ensure nonzero widths and heights, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted .webp file.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-5092

    Last Modified: 20 Apr 2025

    Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-5093

    Last Modified: 20 Apr 2025

    Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to prevent a full screen warning from being displayed via a crafted HTML page.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-5095

    Last Modified: 20 Apr 2025

    Stack overflow in PDFium in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to potentially exploit stack corruption via a crafted PDF file.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-5099

    Last Modified: 20 Apr 2025

    Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially gain privilege elevation via a crafted HTML page.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-5100

    Last Modified: 20 Apr 2025

    A use after free in Apps in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 25 Jul 2017
    4.3
    Medium

    CVE-2017-5102

    Last Modified: 20 Apr 2025

    Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 25 Jul 2017
    4.3
    Medium

    CVE-2017-5103

    Last Modified: 20 Apr 2025

    Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-5104

    Last Modified: 20 Apr 2025

    Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the omnibox via a crafted HTML page.

    Published: 25 Jul 2017
    5.4
    Medium

    CVE-2017-1287

    Last Modified: 20 Apr 2025

    IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim.

    Published: 24 Jul 2017
    5.4
    Medium

    CVE-2016-8975

    Last Modified: 20 Apr 2025

    IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118912.

    Published: 24 Jul 2017
    5.4
    Medium

    CVE-2017-1380

    Last Modified: 20 Apr 2025

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127151.

    Published: 24 Jul 2017
    7.1
    High

    CVE-2017-1382

    Last Modified: 20 Apr 2025

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force ID: 127153.

    Published: 24 Jul 2017
    5.4
    Medium

    CVE-2016-6118

    Last Modified: 20 Apr 2025

    IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118356.

    Published: 24 Jul 2017
    5.4
    Medium

    CVE-2017-1245

    Last Modified: 20 Apr 2025

    IBM Rational Software Architect Design Manager 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124580.

    Published: 24 Jul 2017
    5.4
    Medium

    CVE-2017-1249

    Last Modified: 20 Apr 2025

    IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 24 Jul 2017
    7.5
    High

    CVE-2017-9553

    Last Modified: 20 Apr 2025

    A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter.

    Published: 24 Jul 2017
    5.3
    Medium

    CVE-2017-9554

    Last Modified: 20 Apr 2025

    An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.

    Published: 24 Jul 2017
    7.8
    High

    CVE-2017-8036

    Last Modified: 20 Apr 2025

    An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release version 1.33.0 (only). The original fix for CVE-2017-8033 included in CAPI-release 1.33.0 introduces a regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application.

    Published: 24 Jul 2017
    Unknown

    CVE-2017-2605

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-1000362. Reason: This candidate is a duplicate of CVE-2017-1000362. A vendor reference identifier was mistakenly treated as a CVE ID. Notes: All CVE users should reference CVE-2017-1000362 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Jul 2017
    Unknown

    CVE-2011-4965

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2011. Notes: none

    Published: 24 Jul 2017
    Unknown

    CVE-2010-1430

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2010. Notes: none

    Published: 24 Jul 2017
    Unknown

    CVE-2011-3608

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0815. Reason: This candidate is a reservation duplicate of CVE-2012-0815. Notes: All CVE users should reference CVE-2012-0815 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Jul 2017
    Unknown

    CVE-2011-4933

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0819. Reason: This candidate is a reservation duplicate of CVE-2012-0819. Notes: All CVE users should reference CVE-2012-0819 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Jul 2017