Latest CVE Feed
-
5.5
MEDIUMCVE-2017-14971
Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted Microsoft Office document containing a link that has a UNC pathname associated with an attacker-controller server. In one specific scena... Read more
Affected Products : infocus_mondopad- Published: Oct. 09, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2018-20947
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-2662
Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.2.11, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7 and 6.4.1. Easily exploitable ... Read more
Affected Products : transportation_management- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-3032
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows... Read more
Affected Products : flexcube_investor_servicing- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-3130
Vulnerability in the PeopleSoft Enterprise Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Application Portal). The supported version that is affected is 9.1.0.0. Easily exploitable vulnerability allows low privileged attacker with ... Read more
Affected Products : peoplesoft_enterprise_prtl_interaction_hub peoplesoft_enterprise_interaction_hub- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-18049
In the CSV export feature of SilverStripe before 3.5.6, 3.6.x before 3.6.3, and 4.x before 4.0.1, it's possible for the output to contain macros and scripts, which may be executed if imported without sanitization into common software (including Microsoft ... Read more
- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-7366
In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-18396
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-9770
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse that can cause an out of bounds read operation to occur due to a field within the IOCTL data being used as a length.... Read more
Affected Products : razer_synapse- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-3232
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the... Read more
Affected Products : automatic_service_request- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-3492
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.0 and 12.1.0. Easily "exploitable" vulnerabi... Read more
Affected Products : flexcube_enterprise_limits_and_collateral_management- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2018-8843
Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing specially crafted Arena Simulation Software files that may cause the software application to crash, potentially losing any unsaved data..... Read more
Affected Products : arena- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-9151
A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allows local non-privileged users to crash the system via IOCTL 0x80030030.... Read more
Affected Products : internet_security_9_plus- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-6007
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to crash the OS via a malformed IOCTL call.... Read more
Affected Products : hitmanpro- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2019-0291
Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise be restricted.... Read more
Affected Products : solution_manager- Published: May. 14, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-0381
A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.... Read more
- Published: Oct. 08, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-6696
A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to gain access to sensitive user credentials that are stored in an affected system. More Information: CSCvd73677. Known Affected Releases... Read more
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-17429
In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL.... Read more
- Published: Jan. 16, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-9451
In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploit... Read more
Affected Products : android- Published: Nov. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12172
Improper password hashing in firmware in Intel Server Board (S7200AP,S7200APR) and Intel Compute Module (HNS7200AP, HNS7200AP) may allow a privileged user to potentially disclose firmware passwords via local access.... Read more
Affected Products : s7200ap_firmware hns7200ap_firmware s7200apr_firmware hns7200apr_firmware hns7200ap hns7200apr s7200apr s7200ap- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024