Latest CVE Feed
-
9.3
HIGHCVE-2017-0593
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to obtain access to custom permissions. This issue is rated as High because it is a general bypass for operating system protections that isolate appli... Read more
Affected Products : android- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5655
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.... Read more
Affected Products : ambari- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9572
The athens-state-bank-mobile-banking/id719748589 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : athens_state_bank_mobile- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7676
Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in unintended behavior.... Read more
Affected Products : ranger- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-0651
An information disclosure vulnerability in the kernel ION subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged process. Product... Read more
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0642
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product:... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8239
In all Android releases from CAF using the Linux kernel, userspace-controlled parameters for flash initialization are not sanitized potentially leading to exposure of kernel memory.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8238
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a camera function.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-7365
In all Android releases from CAF using the Linux kernel, a buffer overread can occur if a particular string is not NULL terminated.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10341
In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2016-9991
IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.... Read more
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9033
In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9030
In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9025
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE application.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-9021
In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1099
IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659.... Read more
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-0254
IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker could exploit this vulnerability to consume all available... Read more
Affected Products : cognos_business_intelligence- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6687
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in to the affected device using default credentials present on the system, aka an Insecure Default... Read more
Affected Products : ultra_services_framework_element_manager- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6686
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated, remote attacker with access to the management network to log in as an admin or oper user of the affected device, aka an Insecure Default Credentials Vulnerabil... Read more
Affected Products : ultra_services_framework_element_manager- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6675
A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system. More Information: CSCvd25405. Known Affected Rel... Read more
Affected Products : industrial_network_director- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025