Latest CVE Feed
-
5.3
MEDIUMCVE-2017-15093
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing n... Read more
Affected Products : recursor- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-15092
A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing a remote attacker to inject HTML and Javascript code in... Read more
Affected Products : recursor- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2017-15091
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been co... Read more
Affected Products : authoritative- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2017-15090
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. Th... Read more
Affected Products : recursor- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-15089
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client,... Read more
Affected Products : infinispan- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2017-15043
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary ... Read more
Affected Products : gx440_firmware es440_firmware ls300_firmware gx400_firmware es450_firmware rv50_firmware rv50x_firmware mp70_firmware mp70e_firmware gx450_firmware +10 more products- Published: May. 04, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-15031
In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.... Read more
Affected Products : arm-trusted-firmware- Published: Dec. 18, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-15030
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).... Read more
Affected Products : open-xchange_appsuite- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-15029
Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.... Read more
Affected Products : open-xchange_appsuite- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-14993
OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition before 6.0.0 RC3 (development), 5.2.x before 5.2.11 (legacy), and 5.3.x before 5.3.6 (maintenance), and P... Read more
Affected Products : eshop- Published: Feb. 20, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-14960
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection.... Read more
Affected Products : document_sciences_xpression- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-14948
Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled ... Read more
Affected Products : dir-895l_firmware dir-890l_firmware dir-885l_firmware dir-880l_firmware dir-868l_firmware dir-895r_firmware dir-890l dir-868l dir-885l dir-895l +2 more products- Published: Oct. 14, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14915
In Android before 2018-01-05 on Qualcomm Snapdragon Mobile SD 625, SD 650/52, SD 835, accessing SPCOM functions with a compromised client structure can result in a Use After Free condition.... Read more
Affected Products : android sd_625_firmware sd_835_firmware sd_650_firmware sd_652_firmware sd_625 sd_650 sd_835 sd_652- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14913
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, SD 625, SD 650/52, SD 835, SD 845, DDR address input validation is being improperly truncated.... Read more
Affected Products : android sd_625_firmware sd_835_firmware mdm9206_firmware sd_650_firmware sd_652_firmware sd_845_firmware mdm9206 sd_625 sd_650 +3 more products- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14912
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile [VERSION]: MDM9206, MDM9607, MDM9650, MSM8909W, SD 200, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 835, the at... Read more
Affected Products : android sd_625_firmware sd_835_firmware mdm9650_firmware msm8909w_firmware mdm9206_firmware mdm9607_firmware sd_410_firmware sd_412_firmware sd_210_firmware +33 more products- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14911
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 625, SD 650/52, SD 820, SD 835, it is possible for the XBL loader to skip th... Read more
Affected Products : msm8996au_firmware sd_625_firmware sd_820_firmware sd_835_firmware apq8096au_firmware mdm9650_firmware mdm9206_firmware sd_210_firmware sd_212_firmware sd_205_firmware +18 more products- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14910
In Snapdragon Automobile, Snapdragon IoT and Snapdragon Mobile MDM9206 MDM9607, MDM9650, S820A, S820Am, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 820, SD 835, and SD 845, a buffer overread is possible... Read more
Affected Products : sd_625_firmware sd_820_firmware sd_835_firmware mdm9650_firmware mdm9206_firmware mdm9607_firmware s820a_firmware sd_410_firmware sd_412_firmware sd_210_firmware +32 more products- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14906
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, PKCS7 padding is not supported by the crypto storage APIs.... Read more
Affected Products : android- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-14894
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, in wma_vdev_start_resp_handler(), vdev id is received from firmware as part of WMI_VDEV_STAR... Read more
Affected Products : android- Published: Apr. 03, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-14893
While flashing meta image, a buffer over-read may potentially occur when the image size is smaller than the image header size or is smaller than the image header size + total image header entry in Android releases from CAF using the linux kernel (Android ... Read more
Affected Products : android- Published: Jul. 06, 2018
- Modified: Nov. 21, 2024