CVEs from 2017
Total
11,679
critical
critical 1,647
high
high 5,041
medium
medium 4,168
low
low 159
% Critical
14.1%
% with KEV
0.7%
% with exploit
9.8%
Top vendors
Top products
- imagemagick 1,426
- joomla\! 932
- kanboard 848
- ntp 762
- tomcat 676
- mahara 572
- postgresql 492
- asterisk 435
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-14608 | critical | 9.1 | 9.1 | 9y ago | In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp. An attacker could possibly exploit this flaw to … | |||
| CVE-2017-12883 | critical | 9.1 | 9.1 | 9y ago | Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of se… | |||
| CVE-2017-0898 | critical | 9.1 | 9.1 | 9y ago | Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting … | |||
| CVE-2017-12249 | critical | 9.1 | 9.1 | 9y ago | A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to… | |||
| CVE-2017-14230 | critical | 9.1 | 9.1 | 9y ago | In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow re… | |||
| CVE-2017-14122 | critical | 9.1 | 9.1 | 9y ago | unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp. | |||
| CVE-2017-10833 | critical | 9.1 | 9.1 | 9y ago | "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to bypass access restriction to view information or modify configurations via unspecified vectors. | |||
| CVE-2017-1383 | critical | 9.1 | 9.1 | 9y ago | IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to exp… | |||
| CVE-2017-11694 | critical | 9.1 | 9.1 | 9y ago | MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability to communicate direct… | |||
| CVE-2017-11693 | critical | 9.1 | 9.1 | 9y ago | MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate … | |||
| CVE-2017-2277 | critical | 9.1 | 9.1 | 9y ago | WG-C10 v3.0.79 and earlier allows an attacker to bypass access restrictions to obtain or alter information stored in the external storage connected to the product via unspecified vectors. | |||
| CVE-2017-9788 | critical | 9.1 | 9.1 | 9y ago | In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assi… | |||
| CVE-2017-11147 | critical | 9.1 | 9.1 | 9y ago | In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due … | |||
| CVE-2017-6711 | critical | 9.1 | 9.1 | 9y ago | A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. The vulne… | |||
| CVE-2017-10917 | critical | 9.1 | 9.1 | 9y ago | Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly o… | |||
| CVE-2017-2782 | critical | 9.1 | 9.1 | 9y ago | An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, l… | |||
| CVE-2017-9097 | critical | 9.1 | 9.1 | 9y ago | In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, a… | |||
| CVE-2017-8841 | high | 8.1 | 9.1 | 9y ago | Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The attack methodology … | |||
| CVE-2017-7337 | critical | 9.1 | 9.1 | 9y ago | An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or enumerate other ADOMs via another user's stolen ses… | |||
| CVE-2017-9053 | critical | 9.1 | 9.1 | 9y ago | An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a failure to check a pointer for being in bounds (in … | |||
| CVE-2017-8872 | critical | 9.1 | 9.1 | 9y ago | The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure. | |||
| CVE-2017-8827 | critical | 9.1 | 9.1 | 9y ago | GeniXCMS Arbitrary User Password Reset Vulnerability | |||
| CVE-2017-7229 | critical | 9.1 | 9.1 | 9y ago | PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from 'Content-Type: multipart/encrypted; protocol="application/pgp-… | |||
| CVE-2017-6520 | critical | 9.1 | 9.1 | 9y ago | The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a de… | |||
| CVE-2017-6519 | critical | 9.1 | 9.1 | 9y ago | avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (tra… | |||
| CVE-2017-3508 | critical | 9.1 | 9.1 | 9y ago | Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration). Supported versions that are affected are 1.0, 1.1, 14.2, 15.1, 15.2,… | |||
| CVE-2017-5648 | critical | 9.1 | 9.1 | 9y ago | Exposure of Resource to Wrong Sphere in Apache Tomcat | |||
| CVE-2017-7357 | critical | 9.1 | 9.1 | 9y ago | Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file. | |||
| CVE-2017-2989 | critical | 9.1 | 9.1 | 9y ago | Adobe Campaign versions Build 8770 and earlier have an input validation bypass that could be exploited to read, write, or delete data from the Campaign database. | |||
| CVE-2017-2447 | high | 8.1 | 9.1 | 9y ago | An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS before 10.2 is affected. The issue involves the "WebKit" component. It allows remo… | |||
| CVE-2017-6412 | high | 8.1 | 9.1 | 9y ago | In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. | |||
| CVE-2017-7226 | critical | 9.1 | 9.1 | 9y ago | The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses… | |||
| CVE-2017-6969 | critical | 9.1 | 9.1 | 9y ago | readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak a… | |||
| CVE-2017-6528 | high | 8.1 | 9.1 | 9y ago | An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file). | |||
| CVE-2017-6351 | high | 8.1 | 9.1 | 9y ago | The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DEBUG mode, an attacker can connect to the device u… | |||
| CVE-2017-2968 | critical | 9.1 | 9.1 | 9y ago | Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability. | |||
| CVE-2017-5152 | critical | 9.1 | 9.1 | 9y ago | An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted (AUTHENTICA… | |||
| CVE-2017-5142 | critical | 9.1 | 9.1 | 9y ago | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user with low privileges is able to open and change the pa… | |||
| CVE-2017-5539 | critical | 9.1 | 9.1 | 10y ago | The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ..\/ to bypass the filter rule. Then, this attacker can exploit t… | |||
| CVE-2017-5545 | critical | 9.1 | 9.1 | 10y ago | The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via App… | |||
| CVE-2017-5209 | critical | 9.1 | 9.1 | 10y ago | The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) vi… | |||
| CVE-2017-18078 | high | — | 9.0 | — | systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass… | |||
| CVE-2017-5123 | high | — | 9.0 | — | Insufficient data validation in waitid allowed an user to escape sandboxes on Linux. | |||
| CVE-2017-9410 | high | — | 9.0 | — | multiple issues in lame | |||
| CVE-2017-9411 | high | — | 9.0 | — | multiple issues in lame | |||
| CVE-2017-5715 | high | — | 9.0 | 4y ago | RHSA-2022:1988: kernel security, bug fix, and enhancement update (Important) | |||
| CVE-2017-5262 | high | 8.0 | 9.0 | 9y ago | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the SNMP read-only (RO) community string has access to sensitive information by OID reference. | |||
| CVE-2017-14591 | critical | 9.0 | 9.0 | 9y ago | Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary cod… | |||
| CVE-2017-13129 | high | 8.0 | 9.0 | 9y ago | Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators … | |||
| CVE-2017-1000251 | high | 8.0 | 9.0 | 9y ago | The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing … | |||
| CVE-2017-10102 | critical | 9.0 | 9.0 | 9y ago | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Diff… | |||
| CVE-2017-4919 | critical | 9.0 | 9.0 | 9y ago | VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate. | |||
| CVE-2017-5691 | critical | 9.0 | 9.0 | 9y ago | Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows… | |||
| CVE-2017-10915 | critical | 9.0 | 9.0 | 9y ago | The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219. | |||
| CVE-2017-2292 | critical | 9.0 | 9.0 | 9y ago | Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.sa… | |||
| CVE-2017-7571 | high | 8.0 | 9.0 | 9y ago | public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. | |||
| CVE-2017-5206 | critical | 9.0 | 9.0 | 9y ago | Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument. | |||
| CVE-2017-0021 | critical | 9.0 | 9.0 | 9y ago | Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Str… | |||
| CVE-2017-2787 | critical | 9.0 | 9.0 | 9y ago | A buffer overflows exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to a heap based buf… | |||
| CVE-2017-5633 | high | 8.0 | 9.0 | 9y ago | Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (… | |||
| CVE-2017-2684 | critical | 9.0 | 9.0 | 9y ago | Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level au… | |||
| CVE-2017-3310 | critical | 9.0 | 9.0 | 10y ago | Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having C… | |||
| CVE-2017-3575 | high | 7.9 | 8.9 | 9y ago | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" v… | |||
| CVE-2017-5149 | high | 8.9 | 8.9 | 9y ago | An issue was discovered in St. Jude Medical Merlin@home, versions prior to Version 8.2.2 (RF models: EX1150; Inductive models: EX1100; and Inductive models: EX1100 with MerlinOnDemand capability). Th… | |||
| CVE-2017-6952 | high | 8.8 | 8.8 | 4y ago | Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or p… | |||
| CVE-2017-17516 | high | 8.8 | 8.8 | 4y ago | scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote att… | |||
| CVE-2017-10784 | high | 8.8 | 8.8 | 4y ago | WEBrick RCE Vulnerability | |||
| CVE-2017-14683 | high | 8.8 | 8.8 | 4y ago | Gem in a Box vulnerable to Cross-site Request Forgery | |||
| CVE-2017-12864 | high | 8.8 | 8.8 | 5y ago | In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or… | |||
| CVE-2017-12862 | high | 8.8 | 8.8 | 5y ago | In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause copy buffer overflow later. If the image is from remote, may lead to remote code … | |||
| CVE-2017-12603 | high | 8.8 | 8.8 | 5y ago | OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in the cv::RLByteStream::getBytes function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::i… | |||
| CVE-2017-12598 | high | 8.8 | 8.8 | 5y ago | OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by … | |||
| CVE-2017-7235 | high | 8.8 | 8.8 | 8y ago | An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website. … | |||
| CVE-2017-17990 | high | 8.8 | 8.8 | 9y ago | Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action. | |||
| CVE-2017-17983 | high | 8.8 | 8.8 | 9y ago | PHP Scripts Mall Muslim Matrimonial Script has SQL injection via the view-profile.php mem_id parameter. | |||
| CVE-2017-17973 | high | 8.8 | 8.8 | 9y ago | In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue | |||
| CVE-2017-17960 | high | 8.8 | 8.8 | 9y ago | PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php. | |||
| CVE-2017-17950 | high | 8.8 | 8.8 | 9y ago | Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter. | |||
| CVE-2017-17942 | high | 8.8 | 8.8 | 9y ago | In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c. | |||
| CVE-2017-17939 | high | 8.8 | 8.8 | 9y ago | PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php. | |||
| CVE-2017-17936 | high | 8.8 | 8.8 | 9y ago | Vanguard Marketplace Digital Products PHP has CSRF via /search. | |||
| CVE-2017-13056 | high | 7.8 | 8.8 | 9y ago | The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file. | |||
| CVE-2017-7160 | high | 8.8 | 8.8 | 9y ago | An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected… | |||
| CVE-2017-7157 | high | 8.8 | 8.8 | 9y ago | An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected… | |||
| CVE-2017-7156 | high | 8.8 | 8.8 | 9y ago | An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected… | |||
| CVE-2017-17930 | high | 8.8 | 8.8 | 9y ago | PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel. | |||
| CVE-2017-17915 | high | 8.8 | 8.8 | 9y ago | In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached. | |||
| CVE-2017-17913 | high | 8.8 | 8.8 | 9y ago | In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use … | |||
| CVE-2017-17912 | high | 8.8 | 8.8 | 9y ago | In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region. | |||
| CVE-2017-17908 | high | 8.8 | 8.8 | 9y ago | PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general. | |||
| CVE-2017-17905 | high | 8.8 | 8.8 | 9y ago | PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php. | |||
| CVE-2017-17903 | high | 8.8 | 8.8 | 9y ago | FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel. | |||
| CVE-2017-17894 | high | 8.8 | 8.8 | 9y ago | Readymade Job Site Script has CSRF via the /job URI. | |||
| CVE-2017-17891 | high | 8.8 | 8.8 | 9y ago | Readymade Video Sharing Script has CSRF via user-profile-edit.php. | |||
| CVE-2017-17888 | high | 8.8 | 8.8 | 9y ago | cgi-bin/write.cgi in Anti-Web through 3.8.7, as used on NetBiter / HMS, Ouman EH-net, Alliance System WS100 --> AWU 500, Sauter ERW100F001, Carlo Gavazzi SIU-DLG, AEDILIS SMART-1, SYXTHSENSE WebBiter… | |||
| CVE-2017-17880 | high | 8.8 | 8.8 | 9y ago | In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to a WEBP_DECODER_ABI_VERSION check. | |||
| CVE-2017-17879 | high | 8.8 | 8.8 | 9y ago | In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based buffer over-read in ReadOneMNGImage in coders/png.c, related to length calculation and caused by an off-by-one error. | |||
| CVE-2017-16995 | high | 7.8 | 8.8 | 9y ago | The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by lev… | |||
| CVE-2017-12736 | high | 8.8 | 8.8 | 9y ago | After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain conditions. This could allow an attacker located in the adjacent network of … | |||
| CVE-2017-13876 | high | 7.8 | 8.8 | 9y ago | An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the … |