Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2017-11495
PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternativ…
K2\(psg1218\) Firmware
after 22.5.11.5
MEDIUM 6.5
CVE-2017-7060
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "Safari Pr…
Safari
10.1.2 / 10.3.3+
MEDIUM 5.5
CVE-2017-7064EPSS 7%
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is…
Safari
after 12.6.1
MEDIUM 5.5
CVE-2017-7045
An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It all…
Mac Os X
after 10.12.5
MEDIUM 6.5
CVE-2017-2517
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attacke…
Iphone Os
after 10.3.2
MEDIUM 6.5
CVE-2017-7011
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "WebKit" c…
Safari
after 10.3.2
HIGH 7.5
CVE-2017-11407
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fr…
Wireshark
after 2.2.7
HIGH 7.5
CVE-2017-11408
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the AMQP dissector could crash. This was addressed in epan/dissectors/packet-amqp.c by checking for …
Wireshark
Patch available
HIGH 7.5
CVE-2017-11410
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed…
Wireshark
Patch available
HIGH 7.5
CVE-2017-11411
In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissec…
Wireshark
Patch available
CRITICAL 9.8
CVE-2017-9811EPSS 8%
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 …
Anti Virus For Linux Server
after 8.0.3.297
HIGH 7.2
CVE-2017-8004
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions …
Rsa Identity Governance And Lifecycle
Mitigation only
CRITICAL 9.8
CVE-2017-2345
On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS snmpd daemon to crash and res…
Junos
Mitigation only
HIGH 7.5
CVE-2017-2347
A denial of service vulnerability in rpd daemon of Juniper Networks Junos OS allows a malformed MPLS ping packet to crash the rpd daemon if MPLS OAM …
Junos
Mitigation only
HIGH 7.5
CVE-2017-2314
Receipt of a malformed BGP OPEN message may cause the routing protocol daemon (rpd) process to crash and restart. By continuously sending specially c…
Junos
Mitigation only
CRITICAL 9.8
CVE-2017-11346EPSS 37%
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk…
Manageengine Desktop Central
after 10.0
MEDIUM 6.5
CVE-2017-11340
There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, related to an exit call. A Crafted input will lead to a remote de…
Exiv2
Mitigation only
HIGH 7.5
CVE-2017-11342
There is an illegal address access in ast.cpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
Libsass
No fix yet
HIGH 7.5
CVE-2017-10605
On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the flowd process to crash, halti…
Junos
Mitigation only
CRITICAL 9.8
CVE-2017-1000039
Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution
Framadate
Mitigation only
HIGH 7.5
CVE-2017-1000048
the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil req…
Qs
Mitigation only
HIGH 7.5
CVE-2017-1000014
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality
phpMyAdmin
Patch available
HIGH 7.5
CVE-2017-1000016
A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA…
phpMyAdmin
Mitigation only
HIGH 7.5
CVE-2017-1000018
phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name
phpMyAdmin
4.0.10.19 / 4.4.15.10+
HIGH 7.5
CVE-2017-1000001
FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.
Fedmsg
after 0.18.1
CRITICAL 9.1
CVE-2017-9788EPSS 54%
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or…
HTTP Server
after 2.4.26
MEDIUM 5.9
CVE-2017-7672EPSS 9%
If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used t…
Struts
Mitigation only
MEDIUM 6.5
CVE-2017-1285
IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to r…
Websphere Mq
Patch available
MEDIUM 6.5
CVE-2017-8599
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page wit…
Edge
Patch available
MEDIUM 6.5
CVE-2017-8602
Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1…
Edge
Patch available