Vulnerabilities (CVE)

Total 398899 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-12599 2 Debian, Opencv 2 Debian Linux, Opencv 2026-06-17 6.8 MEDIUM 8.8 HIGH
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the function icvCvt_BGRA2BGR_8u_C4C3R when reading an image file by using cv::imread.
CVE-2017-12598 2 Debian, Opencv 2 Debian Linux, Opencv 2026-06-17 6.8 MEDIUM 8.8 HIGH
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 8-opencv-invalid-read-fread test case.
CVE-2017-12597 2 Debian, Opencv 2 Debian Linux, Opencv 2026-06-17 6.8 MEDIUM 8.8 HIGH
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread.
CVE-2017-12596 1 Openexr 1 Openexr 2026-06-17 6.8 MEDIUM 7.8 HIGH
In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it may result in denial of service or possibly unspecified other impact.
CVE-2017-12595 1 Qpdf Project 1 Qpdf 2026-06-17 6.8 MEDIUM 7.8 HIGH
The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other impact via a PDF document with a deep data structure, as demonstrated by a crash in QPDFObjectHandle::parseInternal in libqpdf/QPDFObjectHandle.cc.
CVE-2017-12593 1 Asus 2 Dsl-n10s Firmware, Dsl-n10s Router 2026-06-17 6.8 MEDIUM 8.8 HIGH
ASUS DSL-N10S V2.1.16_APAC devices allow CSRF.
CVE-2017-12592 1 Asus 2 Dsl-n10s, Dsl-n10s Firmware 2026-06-17 6.5 MEDIUM 8.8 HIGH
ASUS DSL-N10S V2.1.16_APAC devices have a privilege escalation vulnerability. A normal user can escalate its privilege and perform administrative actions. There is no mapping of users with their privileges.
CVE-2017-12591 1 Asus 2 Dsl-n10s, Dsl-n10s Firmware 2026-06-17 3.5 LOW 5.4 MEDIUM
ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter.
CVE-2017-12590 1 Asus 2 Rt-n14uhp, Rt-n14uhp Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
ASUS RT-N14UHP devices before 3.0.0.4.380.8015 have a reflected XSS vulnerability in the "flag" parameter.
CVE-2017-12589 1 Tomaxcom 4 R60g, R60g Firmware, R60gv2 and 1 more 2026-06-17 6.8 MEDIUM 8.8 HIGH
ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.
CVE-2017-12588 1 Rsyslog 1 Rsyslog 2026-06-17 7.5 HIGH 9.8 CRITICAL
The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact.
CVE-2017-12587 1 Imagemagick 1 Imagemagick 2026-06-17 6.8 MEDIUM 8.8 HIGH
ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.
CVE-2017-12586 1 Slims 1 Akasia 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
SLiMS 8 Akasia through 8.3.1 has an arbitrary file reading issue because of directory traversal in the url parameter to admin/help.php. It can be exploited by remote authenticated librarian users.
CVE-2017-12585 1 Slims 1 Akasia 2026-06-17 6.5 MEDIUM 8.8 HIGH
SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users.
CVE-2017-12584 1 Slims 1 Senayan Library Management System 2026-06-17 6.8 MEDIUM 8.8 HIGH
There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attacker-controlled password, a complete account takeover, via the passwd1 and passwd2 fields in an admin/modules/system/app_user.php changecurrent=true operation.
CVE-2017-12583 1 Dokuwiki 1 Dokuwiki 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php.
CVE-2017-12582 1 Qnap 2 Ts-212p, Ts-212p Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveillance Station.
CVE-2017-12581 1 Electron 1 Electron 2026-06-17 9.3 HIGH 8.1 HIGH
GitHub Electron before 1.6.8 allows remote command execution because of a nodeIntegration bypass vulnerability. This also affects all applications that bundle Electron code equivalent to 1.6.8 or earlier. Bypassing the Same Origin Policy (SOP) is a precondition; however, recent Electron versions do not have strict SOP enforcement. Combining an SOP bypass with a privileged URL internally used by Electron, it was possible to execute native Node.js primitives in order to run OS commands on the user's host. Specifically, a chrome-devtools://devtools/bundled/inspector.html window could be used to eval a Node.js child_process.execFile API call.
CVE-2017-12580 1 Ultraedit 1 Ultraedit 2026-06-17 6.9 MEDIUM 7.8 HIGH
An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affected executable a DLL using the name of a Windows DLL. This DLL must be preloaded by the executable (for example, "ntmarta.dll"). When the installer EXE is executed by the user, the DLL located in the EXE's current directory will be loaded instead of the Windows DLL, allowing the attacker to run arbitrary code on the affected system.
CVE-2017-12579 1 Hashicorp 1 Vagrant Vmware Fusion 2026-06-17 7.2 HIGH 7.8 HIGH
An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.