Latest CVE Feed
-
4.6
MEDIUMCVE-2017-5625
In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') by issuing the 'fastboot oem dump <partition>' fastboot com... Read more
- Published: Apr. 25, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-3583
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access). Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerabi... Read more
Affected Products : primavera_p6_enterprise_project_portfolio_management- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-3580
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: RAS subsystems). The supported version that is affected is AK 2013. Difficult to exploit vulnerability allows unauthenticated attacker wi... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6917
Buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2016-6903
lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.... Read more
Affected Products : lshell- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
2.8
LOWCVE-2016-5551
Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). The supported version that is affected is 4.3. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the in... Read more
Affected Products : solaris_cluster- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-5016
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does ... Read more
Affected Products : cloud_foundry_elastic_runtime cloud_foundry_uaa cloud_foundry_uaa-release cloud_foundry- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8100
There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings.... Read more
Affected Products : copysafe_web_protection- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-2322
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authenticated user to cause widespread denials of service to system services by consuming TCP and UDP ports which ar... Read more
Affected Products : northstar_controller- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-3691
Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method.... Read more
Affected Products : kallithea- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-7569
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.... Read more
Affected Products : yeager_cms- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2332
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network based, unauthenticated attacker to perform privileged actions to gain complete control o... Read more
Affected Products : northstar_controller- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2017-2329
An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to execute certain specific unprivileged system files capable of causing... Read more
Affected Products : northstar_controller- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8082
concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&im... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2015-8109
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "t... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-1522
analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a packet length, which allows remote attackers to cause a denial of service (buffer overflow or buffer over-read) via a crafted DNP3 packet.... Read more
Affected Products : bro- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8065
crypto/ccm.c in the Linux kernel 4.9.x and 4.10.x through 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact ... Read more
Affected Products : linux_kernel- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8061
drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.x before 4.10.7 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly ... Read more
Affected Products : linux_kernel- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-3067
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.... Read more
Affected Products : cygwin- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-1561
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.... Read more
Affected Products : ex3000_firmware ex5000_firmware ex7000_firmware ex10000e_firmware ex13000e_firmware ex21000e_firmware ex32000e_firmware ex40000e_firmware ex3000 ex5000 +6 more products- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025