CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2017-6097

    Last Modified: 20 Apr 2025

    A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id.

    Published: 21 Feb 2017
    7.2
    High

    CVE-2017-6098

    Last Modified: 20 Apr 2025

    A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.

    Published: 21 Feb 2017
    9.9
    Critical

    CVE-2016-9269

    Last Modified: 20 Apr 2025

    Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to run arbitrary commands on the system as root via Patch Update functionality. This was resolved in Version 6.5 CP 1737.

    Published: 21 Feb 2017
    5.5
    Medium

    CVE-2017-2620

    Last Modified: 21 Nov 2024

    Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.

    Published: 21 Feb 2017
    7.1
    High

    CVE-2017-6313

    Last Modified: 20 Apr 2025

    Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file.

    Published: 21 Feb 2017
    5.5
    Medium

    CVE-2017-6314

    Last Modified: 20 Apr 2025

    The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file.

    Published: 21 Feb 2017
    6.5
    Medium

    CVE-2017-6414

    Last Modified: 20 Apr 2025

    Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.

    Published: 21 Feb 2017
    5.5
    Medium

    CVE-2017-6312

    Last Modified: 20 Apr 2025

    Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.

    Published: 21 Feb 2017
    7.8
    High

    CVE-2017-6347

    Last Modified: 20 Apr 2025

    The ip_cmsg_recv_checksum function in net/ipv4/ip_sockglue.c in the Linux kernel before 4.10.1 has incorrect expectations about skb data layout, which allows local users to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted system calls, as demonstrated by use of the MSG_MORE flag in conjunction with loopback UDP transmission.

    Published: 21 Feb 2017
    5.5
    Medium

    CVE-2017-0038

    Last Modified: 20 Apr 2025

    gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220.

    Published: 20 Feb 2017
    5.3
    Medium

    CVE-2016-6249

    Last Modified: 20 Apr 2025

    F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in plaintext to /var/log/restjavad.0.log. It may allow local users to obtain sensitive information by reading these files.

    Published: 20 Feb 2017
    6.1
    Medium

    CVE-2016-7762

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "WebKit" component, which allows XSS attacks against Safari.

    Published: 20 Feb 2017
    4.6
    Medium

    CVE-2017-2352

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Unlock with iPhone" component, which allows attackers to bypass the wrist-presence protection mechanism and unlock a Watch device via unspecified vectors.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2017-2353

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2017-2370

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (buffer overflow) via a crafted app.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2017-2359

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. Safari before 10.0.3 is affected. The issue involves the "Safari" component, which allows remote attackers to spoof the address bar via a crafted web site.

    Published: 20 Feb 2017
    6.1
    Medium

    CVE-2017-2361

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer" component, which allows XSS attacks via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2017-2362

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2017-2366

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2017-2368

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" component. It allows remote attackers to cause a denial of service (application crash) via a crafted contact card.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2017-2369

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2017-2360

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

    Published: 20 Feb 2017
    2.4
    Low

    CVE-2017-2351

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WiFi" component, which allows physically proximate attackers to bypass the activation-lock protection mechanism and view the home screen via unspecified vectors.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2017-2355

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2017-2356

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    3.3
    Low

    CVE-2017-2357

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "IOAudioFamily" component. It allows attackers to obtain sensitive kernel memory-layout information via a crafted app.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2017-2363

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2017-2364

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2017-2365

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2017-2372

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. GarageBand before 10.1.5 is affected. Logic Pro X before 10.3 is affected. The issue involves the "Projects" component, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted GarageBand project file.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2017-2373

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7578

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    5.9
    Medium

    CVE-2016-7579

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. The issue involves the "CFNetwork Proxies" component, which allows man-in-the-middle attackers to spoof a proxy password authentication requirement and obtain sensitive information.

    Published: 20 Feb 2017
    6.5
    Medium

    CVE-2016-7586

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to obtain sensitive information via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7587

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7594

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "ICU" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    6.8
    Medium

    CVE-2016-7601

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Local Authentication" component, which does not honor the configured screen-lock time interval if the Touch ID prompt is visible.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7608

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireFamily" component, which allows local users to obtain sensitive information from kernel memory via unspecified vectors.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7615

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component, which allows local users to cause a denial of service via unspecified vectors.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7622

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Grapher" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .gcx file.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7629

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7632

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    5.9
    Medium

    CVE-2016-7636

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which allows man-in-the-middle attackers to cause a denial of service (application crash) via vectors related to OCSP responder URLs.

    Published: 20 Feb 2017
    8.1
    High

    CVE-2016-7643

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "ImageIO" component. It allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7648

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7658

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7665

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Graphics Driver" component, which allows remote attackers to cause a denial of service via a crafted video.

    Published: 20 Feb 2017
    3.3
    Low

    CVE-2016-7714

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOKit" component. It allows local users to obtain sensitive kernel memory-layout information via unspecified vectors.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7742

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "xar" component, which allows remote attackers to execute arbitrary code via a crafted archive that triggers use of uninitialized memory locations.

    Published: 20 Feb 2017
    4.3
    Medium

    CVE-2016-7759

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10 is affected. The issue involves the "Springboard" component, which allows physically proximate attackers to obtain sensitive information by viewing application snapshots in the Task Switcher.

    Published: 20 Feb 2017