Latest CVE Feed
-
5.3
MEDIUMCVE-2017-11022
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the probe requests originated from user's phone contains the information elements which specifies the supported wifi features. This shall impac... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11017
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a specially crafted UBI image, it is possible to corrupt memory, or access uninitialized memory.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11014
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while parsing a Measurement Request IE in a Roam Neighbor Action Report, a buffer overflow can occur.... Read more
Affected Products : android- EPSS Score: %0.18
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11012
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, when processing a specially crafted QCA_NL80211_VENDOR_SUBCMD_ENCRYPTION_TEST cfg80211 vendor command a stack-based buffer overflow can occur.... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-4932
VMware AirWatch Launcher for Android prior to 3.2.2 contains a vulnerability that could allow an escalation of privilege from the launcher UI context menu to native UI functionality and privilege. Successful exploitation of this issue could result in an e... Read more
- EPSS Score: %0.04
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16867
Amazon Key through 2017-11-16 mishandles Cloud Cam 802.11 deauthentication frames during the delivery process, which makes it easier for (1) delivery drivers to freeze a camera and re-enter a house for unfilmed activities or (2) attackers to freeze a came... Read more
- EPSS Score: %1.10
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16851
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.... Read more
- EPSS Score: %12.31
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12323
Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an ... Read more
- EPSS Score: %0.16
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12322
Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an ... Read more
Affected Products : email_encryption- EPSS Score: %0.16
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12321
Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an ... Read more
- EPSS Score: %0.16
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12318
A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker to prevent an affected device from delivering switched digital video (SDV) or video on demand (VoD) streams, resulting in a denial of se... Read more
- EPSS Score: %0.66
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12316
A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform multiple login attempts in excess of the configured login attempt limit. The vulnerability is due to insuffic... Read more
- EPSS Score: %1.19
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12314
A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to the device availability, confidentiality, and integrity, aka Insecure Li... Read more
Affected Products : findit_network_discovery_utility- EPSS Score: %0.07
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-12313
An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes t... Read more
Affected Products : packet_tracer- EPSS Score: %0.06
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12309
A vulnerability in the Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a HTTP response splitting attack. The vulnerability is due to the failure of the application or its environment to properly sanitize inp... Read more
- EPSS Score: %0.98
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12299
A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall Services that could allow an unauthenticated, remote attacker to send traffic to the local IP address of the device, by... Read more
Affected Products : firepower_extensible_operating_system- EPSS Score: %0.23
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-13136
The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference.... Read more
Affected Products : libbpg- EPSS Score: %0.49
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-16842
Cross-site scripting (XSS) vulnerability in admin/google_search_console/class-gsc-table.php in the Yoast SEO plugin before 5.8.0 for WordPress allows remote attackers to inject arbitrary web script or HTML.... Read more
- EPSS Score: %0.07
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5532
A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, T... Read more
Affected Products : jasperreports_server jaspersoft jaspersoft_reporting_and_analytics jasperreports_library jaspersoft_studio jasperreports_library_for_activematrix_bpm jasperreports_server_community_edition jasperreports_server_for_activematrix_bpm jaspersoft_for_aws_with_multi-tenancy jaspersoft_reporting_and_analytics_for_aws +1 more products- EPSS Score: %0.27
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-0219
Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports.... Read more
Affected Products : karaf- EPSS Score: %0.08
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025