Latest CVE Feed
-
7.2
HIGHCVE-2015-6592
Huawei UAP2105 before V300R012C00SPC160(BootRom) does not require authentication to the serial port or the VxWorks shell.... Read more
- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-4669
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.... Read more
Affected Products : xsuite- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1555
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545.... Read more
Affected Products : api_connect- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14716
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.... Read more
Affected Products : epesi- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14715
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.... Read more
Affected Products : epesi- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14079
Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.... Read more
Affected Products : mobile_security- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-3770
Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system.... Read more
Affected Products : xclarity_administrator- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14688
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to a "Read Access Violation starting at STDUDjVuFile!DllUnregisterServer+0x000000000000d917."... Read more
Affected Products : stdu_viewer- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9283
An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed.... Read more
Affected Products : visibroker- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9281
An integer overflow (CWE-190) potentially causing an out-of-bounds read (CWE-125) vulnerability in Micro Focus VisiBroker 8.5 can lead to a denial of service.... Read more
Affected Products : visibroker- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14646
The AP4_AvccAtom and AP4_HvccAtom classes in Bento4 version 1.5.0-617 do not properly validate data sizes, leading to a heap-based buffer over-read and application crash in AP4_DataBuffer::SetData in Core/Ap4DataBuffer.cpp.... Read more
Affected Products : bento4- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14642
A NULL pointer dereference was discovered in the AP4_HdlrAtom class in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash in AP4_StdcFileByteStream::ReadPartial in System/StdC/Ap4StdCFileByteStream.cpp, which lea... Read more
Affected Products : bento4- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14640
A NULL pointer dereference was discovered in AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.... Read more
Affected Products : bento4- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-14320
Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter uploaded files.... Read more
Affected Products : helpdesk_mx- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9677
In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, variable "ddp->params_length" could be accessed and modified by multiple threads, while it is not protected with locks. If one thread is ru... Read more
Affected Products : android- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11001
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.... Read more
Affected Products : android- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-10996
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fatal, however the device might crash/reboot with memory v... Read more
Affected Products : android- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12214
A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerabili... Read more
Affected Products : unified_customer_voice_portal- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14616
An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface with an XML message containing an empty member element, the wgagent crashes, logging out any user with a session opened in the UI. By ... Read more
Affected Products : fireware- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14615
An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interface, if JavaScript code, properly encoded to be consumed by XML parsers, is embedded as value of the user e... Read more
Affected Products : fireware- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025