Total
10071 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-12070 | 1 Opcfoundation | 1 Ua-.net-legacy | 2024-02-04 | 6.8 MEDIUM | 8.8 HIGH |
Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code. | |||||
CVE-2018-1000002 | 1 Nic | 1 Knot Resolver | 2024-02-04 | 4.3 MEDIUM | 3.7 LOW |
Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay. | |||||
CVE-2018-0560 | 1 Hatena | 1 Hatena Bookmark | 2024-02-04 | 4.3 MEDIUM | 6.5 MEDIUM |
Hatena Bookmark App for iOS Version 3.0 to 3.70 allows remote attackers to spoof the address bar via vectors related to URL display. | |||||
CVE-2017-13890 | 1 Apple | 1 Mac Os X | 2024-02-04 | 4.3 MEDIUM | 7.4 HIGH |
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. macOS before 10.13 is affected. The issue involves the "CoreTypes" component. It allows remote attackers to trigger disk-image mounting via a crafted web site. | |||||
CVE-2018-5488 | 1 Netapp | 2 Santricity Storage Manager, Santricity Web Services Proxy | 2024-02-04 | 7.5 HIGH | 9.8 CRITICAL |
NetApp SANtricity Web Services Proxy versions 1.10.x000.0002 through 2.12.X000.0002 and SANtricity Storage Manager 11.30.0X00.0004 through 11.42.0X00.0001 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are susceptible to unauthenticated remote code execution. | |||||
CVE-2017-1000391 | 1 Jenkins | 1 Jenkins | 2024-02-04 | 4.9 MEDIUM | 7.3 HIGH |
Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk. These directories used the user ID for their name without additional escaping, potentially resulting in problems like overwriting of unrelated configuration files. | |||||
CVE-2017-18235 | 1 Exempi Project | 1 Exempi | 2024-02-04 | 4.3 MEDIUM | 5.5 MEDIUM |
An issue was discovered in Exempi before 2.4.3. The VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp does not ensure nonzero widths and heights, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted .webp file. | |||||
CVE-2018-12561 | 1 Cantata Project | 1 Cantata | 2024-02-04 | 6.5 MEDIUM | 8.8 HIGH |
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. A regular user can inject additional mount options such as file_mode= by manipulating (for example) the domain parameter of the samba URL. | |||||
CVE-2017-9270 | 1 Opensuse | 1 Cryptctl | 2024-02-04 | 8.5 HIGH | 9.1 CRITICAL |
In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database. | |||||
CVE-2018-8821 | 1 Jungo | 1 Windriver | 2024-02-04 | 7.1 HIGH | 5.5 MEDIUM |
windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafted .exe file. | |||||
CVE-2018-8945 | 2 Gnu, Redhat | 4 Binutils, Enterprise Linux Desktop, Enterprise Linux Server and 1 more | 2024-02-04 | 4.3 MEDIUM | 5.5 MEDIUM |
The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (segmentation fault) via a large attribute section. | |||||
CVE-2017-16113 | 1 Parsejson Project | 1 Parsejson | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed. | |||||
CVE-2018-7658 | 1 Softros | 1 Network Time System | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service (daemon crash) by sending exactly 11 bytes. | |||||
CVE-2017-1000397 | 1 Jenkins | 1 Maven | 2024-02-04 | 4.3 MEDIUM | 5.9 MEDIUM |
Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-2012-6153 that incorrectly verified SSL certificates, making it susceptible to man-in-the-middle attacks. Maven Plugin 3.0 no longer has a dependency on commons-httpclient. | |||||
CVE-2017-17148 | 1 Huawei | 2 Dp300, Dp300 Firmware | 2024-02-04 | 4.9 MEDIUM | 5.5 MEDIUM |
Huawei DP300 V500R002C00 have a DoS vulnerability due to the lack of validation when the malloc is called. An authenticated local attacker can craft specific XML files to the affected products and parse this file, which result in DoS attacks. | |||||
CVE-2018-10952 | 1 2345 Security Guard Project | 1 2345 Security Guard | 2024-02-04 | 6.1 MEDIUM | 7.8 HIGH |
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222088. | |||||
CVE-2017-5417 | 1 Mozilla | 1 Firefox | 2024-02-04 | 5.0 MEDIUM | 5.3 MEDIUM |
When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the addressbar so that the displayed location following navigation does not match the URL of the newly loaded page. This allows for spoofing attacks. This vulnerability affects Firefox < 52. | |||||
CVE-2017-12473 | 1 Ccn-lite | 1 Ccn-lite | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
ccnl_ccntlv_bytes2pkt in CCN-lite allows context-dependent attackers to cause a denial of service (application crash) via vectors involving packets with "wrong L values." | |||||
CVE-2018-7162 | 1 Nodejs | 1 Node.js | 2024-02-04 | 7.8 HIGH | 7.5 HIGH |
All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This vulnerability has been addressed by updating the TLS implementation. | |||||
CVE-2018-6772 | 1 Jiangmin | 1 Antivirus | 2024-02-04 | 6.1 MEDIUM | 7.8 HIGH |
In Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x99008208. |