CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-18218

    Last Modified: 21 Nov 2024

    In drivers/net/ethernet/hisilicon/hns/hns_enet.c in the Linux kernel before 4.13, local users can cause a denial of service (use-after-free and BUG) or possibly have unspecified other impact by leveraging differences in skb handling between hns_nic_net_xmit_hw and hns_nic_net_xmit.

    Published: 6 Jul 2017
    8.2
    High

    CVE-2017-6707

    Last Modified: 20 Apr 2025

    A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 Series, and 5700 Series devices and Cisco Virtualized Packet Core (VPC) Software could allow an authenticated, local attacker to break from the StarOS CLI of an affected system and execute arbitrary shell commands as a Linux root user on the system, aka Command Injection. The vulnerability exists because the affected operating system does not sufficiently sanitize commands before inserting them into Linux shell commands. An attacker could exploit this vulnerability by submitting a crafted CLI command for execution in a Linux shell command as a root user. Cisco Bug IDs: CSCvc69329, CSCvc72930.

    Published: 6 Jul 2017
    8.8
    High

    CVE-2017-6712

    Last Modified: 20 Apr 2025

    A vulnerability in certain commands of Cisco Elastic Services Controller could allow an authenticated, remote attacker to elevate privileges to root and run dangerous commands on the server. The vulnerability occurs because a "tomcat" user on the system can run certain shell commands, allowing the user to overwrite any file on the filesystem and elevate privileges to root. This vulnerability affects Cisco Elastic Services Controller prior to releases 2.3.1.434 and 2.3.2. Cisco Bug IDs: CSCvc76634.

    Published: 6 Jul 2017
    9.8
    Critical

    CVE-2017-7512

    Last Modified: 20 Apr 2025

    Red Hat 3scale (aka RH-3scale) API Management Platform (AMP) before 2.0.0 would permit creation of an access token without a client secret. An attacker could use this flaw to circumvent authentication controls and gain access to restricted APIs. NOTE: some sources have a typo in which CVE-2017-7512 maps to an OpenVPN vulnerability. The proper CVE ID for that OpenVPN vulnerability is CVE-2017-7521. Specifically, CVE-2017-7521 is the correct CVE ID for TWO closely related findings in OpenVPN. Any source that lists BOTH CVE-2017-7512 and CVE-2017-7521 for OpenVPN should have listed ONLY CVE-2017-7521.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-8826

    Last Modified: 20 Apr 2025

    FastStone Image Viewer 6.2 has a "User Mode Write AV" issue, possibly related to the jpeg_mem_term function in jmemnobs.c in libjpeg. This issue can be triggered by a malformed JPEG file that is mishandled by FSViewer.exe. Attackers could exploit this issue for DoS (Access Violation) or possibly unspecified other impact.

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9529

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx+0x0000000000004efd."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9535

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!GetPlugInInfo+0x0000000000016e53."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9536

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x00000000000014eb."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9874

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000007822."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9876

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000c995."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9879

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls subsequent Write Address starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a525."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9912

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x0000000000000393."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9919

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpResCompareResourceNames+0x0000000000000087."

    Published: 5 Jul 2017
    8.8
    High

    CVE-2017-9926

    Last Modified: 20 Apr 2025

    In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted file, related to a "Read Access Violation starting at image00000000_00400000+0x000000000001b596."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9880

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at FPX+0x0000000000007236."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9884

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000001b6."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9887

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX+0x000000000000688d."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9896

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at Xfpx!gffGetFormatInfo+0x0000000000013e8a."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9905

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at Xfpx!gffGetFormatInfo+0x00000000000228e8."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9911

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at Xfpx+0x0000000000010e81."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10730

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d96."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10737

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000002e6."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10744

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Read Access Violation on Control Flow starting at COMCTL32!CToolTipsMgr::s_ToolTipsWndProc+0x0000000000000032."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10751

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at GDI32!GenericEngineGetGlyphs+0x0000000000000133."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10758

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCoalesceFreeBlocks+0x00000000000004b4."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10764

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at COMCTL32!Tab_OnGetItem+0x000000000000002f."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10770

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpCreateSplitBlock+0x000000000000053a."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10777

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at xnview+0x0000000000372b24."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-8369

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) has a "Data from Faulting Address controls Branch Selection starting at USER32!wvsprintfA+0x00000000000002f3" issue, which might allow attackers to execute arbitrary code via a crafted file.

    Published: 5 Jul 2017
    6.5
    Medium

    CVE-2017-8420

    Last Modified: 20 Apr 2025

    SWFTools 2013-04-09-1007 on Windows has a "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x0000000000003e71" issue. This issue can be triggered by a malformed TTF file that is mishandled by font2swf. Attackers could exploit this issue for DoS (Access Violation).

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9528

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x0000000000000f53."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9886

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpLowFragHeapFree+0x000000000000001f."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9895

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at Xfpx!gffGetFormatInfo+0x0000000000020e95."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9903

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx+0x00000000000117ff."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9904

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpLowFragHeapFree+0x000000000000001f."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9906

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at Xfpx!gffGetFormatInfo+0x0000000000028508."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9908

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to a "Read Access Violation starting at Xfpx+0x000000000000d6da."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-9918

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at KERNELBASE!QueryOptionalDelayLoadedAPI+0x0000000000000c42."

    Published: 5 Jul 2017
    8.8
    High

    CVE-2017-9925

    Last Modified: 20 Apr 2025

    In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10726

    Last Modified: 20 Apr 2025

    Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Data from Faulting Address may be used as a return value starting at f263!GetWinamp5SystemComponent+0x0000000000001951."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10727

    Last Modified: 20 Apr 2025

    Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Data from Faulting Address controls Branch Selection starting at in_mp3!DeleteAudioDecoder+0x000000000000762f."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10728

    Last Modified: 20 Apr 2025

    Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10729

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at ntdll_77df0000!RtlpWaitOnCriticalSection+0x0000000000000121."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10731

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d80."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10732

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpAllocateHeap+0x0000000000000429."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10733

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpEnterCriticalSectionContended+0x0000000000000031."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10734

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to an "Invalid Handle starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10735

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpFreeHeap+0x00000000000003ca."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10736

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at msvcrt!_VEC_memzero+0x000000000000006a."

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10738

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x000000002f32332f called from KERNELBASE!CompareStringW+0x0000000000000082."

    Published: 5 Jul 2017