Latest CVE Feed
-
9.9
CRITICALCVE-2017-16256
Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow ... Read more
- EPSS Score: %0.08
- Published: Jan. 11, 2023
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2017-16255
An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. ... Read more
- EPSS Score: %0.92
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2017-16254
An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. ... Read more
- EPSS Score: %0.92
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2017-16253
An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012 for the cc channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can ... Read more
- EPSS Score: %1.13
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2017-16252
Specially crafted commands sent through the PubNub service in Insteon Hub 2245-222 with firmware version 1012 can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnera... Read more
- EPSS Score: %0.66
- Published: Aug. 06, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2017-16251
A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST request. Successful exploit could allow an attacker to execu... Read more
Affected Products : st14.2- EPSS Score: %1.52
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-16250
A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could be used to identify valid user ids and associated user names.... Read more
Affected Products : st14.2- EPSS Score: %0.23
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2017-16242
An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data access can be bypassed. An attacker with physical access can send a static packet to a serial port exposed on t... Read more
- EPSS Score: %0.06
- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-16232
LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue... Read more
- EPSS Score: %1.74
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-16231
In PCRE 8.41, after compiling, a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c because of a self-recursive call. NOTE: third parties dispute the relevance of this report, noting that there are options that can be ... Read more
Affected Products : pcre- EPSS Score: %0.10
- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-16229
In the Ox gem 2.8.1 for Ruby, the process crashes with a stack-based buffer over-read in the read_from_str function in sax_buf.c when a crafted input is supplied to sax_parse.... Read more
Affected Products : ox- EPSS Score: %0.16
- Published: Feb. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-16226
The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.... Read more
Affected Products : static-eval- EPSS Score: %1.33
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-16225
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (that performed a aegir-release) GitHub token.... Read more
Affected Products : aegir- EPSS Score: %0.32
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-16224
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.... Read more
Affected Products : st- EPSS Score: %0.22
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-16223
nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more
Affected Products : nodeaaaaa- EPSS Score: %0.56
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2017-16222
elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the filesystem by placing "../" in the url. The files accessible, however, are limited to files with a file extension. Sending a GET request... Read more
Affected Products : elding- EPSS Score: %0.19
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-16221
yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more
Affected Products : yzt- EPSS Score: %0.56
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-16220
wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more
Affected Products : wind-mvc- EPSS Score: %0.56
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-16219
yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more
Affected Products : yttivy- EPSS Score: %0.56
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-16218
dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.... Read more
Affected Products : dgard8.lab6- EPSS Score: %0.56
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024