Latest CVE Feed
-
7.8
HIGHCVE-2017-11030
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the HDMI video driver function hdmi_edid_sysfs_rda_res_info(), userspace can perform an arbitrary write into kernel memory.... Read more
Affected Products : android- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17066
The (1) i2pd before 2.17 and (2) kovri pre-alpha implementations of the I2P routing protocol do not properly handle Garlic DeliveryTypeTunnel packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets th... Read more
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-17113
ntguard_x64.sys 0.18780.0.0 in IKARUS anti.virus 2.16.15 has a NULL pointer dereference via a 0x830000c4 DeviceIoControl request.... Read more
- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-16930
The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler. This can be exploited via a long API request that is misha... Read more
Affected Products : claymore_dual_miner- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
8.5
HIGHCVE-2017-16929
The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a remote attacker to read/write arbitrary files. This can be... Read more
Affected Products : claymore_dual_miner- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17057
There is a reflected XSS vulnerability in ZKTime Web 2.0.1.12280. The vulnerability exists due to insufficient filtration of user-supplied data in the 'Range' field of the 'Department' module in a Personnel Advanced Query. A remote attacker can execute ar... Read more
Affected Products : zktime_web- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17096
Cross-site scripting (XSS) vulnerability in the Content Cards plugin before 0.9.7 for WordPress allows remote attackers to inject arbitrary JavaScript via crafted OpenGraph data.... Read more
Affected Products : content_cards- Published: Dec. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14486
The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages with other apps and the PLAIN SASL mechanism to send auth tokens to Vibease servers, which allows remote attackers to obtain user cred... Read more
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15701
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eve... Read more
Affected Products : qpid_broker-j- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10895
sDNSProxy.exe ver1.1.0.0 and earlier allows remote attackers to cause a denial of service via unspecified vectors.... Read more
Affected Products : sdnsproxy- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10894
StreamRelay.NET.exe ver2.14.0.7 and earlier allows remote attackers to cause a denial of service via unspecified vectors.... Read more
Affected Products : streamrelay- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14949
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is re... Read more
Affected Products : restlet- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12362
A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to video calls being made on systems wi... Read more
Affected Products : meeting_server- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12358
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The... Read more
Affected Products : jabber- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12348
Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of ... Read more
Affected Products : unified_computing_system_central_software- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14389
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creatin... Read more
- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14198
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.... Read more
Affected Products : matrix- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14197
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins.... Read more
Affected Products : matrix- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14196
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.... Read more
Affected Products : matrix- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-14378
EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow attackers to bypass authentication, aka an "Error Handling Vulnerability."... Read more
- Published: Nov. 29, 2017
- Modified: Apr. 20, 2025