Latest CVE Feed
-
10.0
HIGHCVE-2017-15366
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client installation on laptops. This password can be used to g... Read more
Affected Products : ndoc- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-15376
The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23.... Read more
Affected Products : mobaxterm- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-15295
Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.... Read more
Affected Products : point_of_sale_xpress_server- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14912
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile [VERSION]: MDM9206, MDM9607, MDM9650, MSM8909W, SD 200, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 835, the at... Read more
Affected Products : android sd_625_firmware sd_835_firmware mdm9650_firmware msm8909w_firmware mdm9206_firmware mdm9607_firmware sd_410_firmware sd_412_firmware sd_210_firmware +33 more products- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14906
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, PKCS7 padding is not supported by the crypto storage APIs.... Read more
Affected Products : android- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14913
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, SD 625, SD 650/52, SD 835, SD 845, DDR address input validation is being improperly truncated.... Read more
Affected Products : android sd_625_firmware sd_835_firmware mdm9206_firmware sd_650_firmware sd_652_firmware sd_845_firmware mdm9206 sd_625 sd_650 +3 more products- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14910
In Snapdragon Automobile, Snapdragon IoT and Snapdragon Mobile MDM9206 MDM9607, MDM9650, S820A, S820Am, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 835, and SD 845, a buffer overread is possible... Read more
Affected Products : sd_625_firmware sd_820_firmware sd_835_firmware mdm9650_firmware mdm9206_firmware mdm9607_firmware s820a_firmware sd_410_firmware sd_412_firmware sd_210_firmware +32 more products- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14803
In NetIQ Access Manager 4.3 and 4.4, a bug exists in Identity Server when accessing a basic SSO connector and downloading the BasicSSO connector plugins on IE11 where an attacker can execute arbitrary code on the system.... Read more
- Published: Jan. 20, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14474
In the MMM::Agent::Helpers::_execute function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1, a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of th... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14480
In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution wi... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2017-14471
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in... Read more
- Published: Apr. 05, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14476
In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2017-14459
An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject comman... Read more
- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2017-14469
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in... Read more
- Published: Apr. 05, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14475
In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with t... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14429
The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root because /etc/services/INET/inet_ipv4.php mishandles shell me... Read more
- Published: Sep. 13, 2017
- Modified: May. 06, 2025
-
10.0
HIGHCVE-2017-14375
EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions... Read more
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14350
A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulnerability could be remotely exploited to allow code execution.... Read more
Affected Products : application_performance_management- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14189
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.... Read more
Affected Products : fortiweb_manager- Published: Nov. 29, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14243
An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administrative settings and obtain cleartext credentials from HTML source, as demonstrated by info.cgi, upload.cgi,... Read more
- Published: Sep. 17, 2017
- Modified: Apr. 20, 2025