Latest CVE Feed
-
8.8
HIGHCVE-2016-10700
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability ... Read more
Affected Products : cacti- Published: Nov. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8201
MAX PRESENCE V100R001C00, TP3106 V100R002C00, TP3206 V100R002C00 have an a memory leak vulnerability in H323 protocol. An attacker logs in to the system as a user and send crafted packets to the affected products. Due to insufficient verification of the p... Read more
Affected Products : tp3106_firmware max_presence_firmware tp3206_firmware tp3106 max_presence tp3206- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14826
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14828
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-9353
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a static key hard-coded in the program. Attackers could reverse the admin account password for use.... Read more
Affected Products : susiaccess- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9303
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code or cause an infinite loop condition when reading or converting malformed FBX format files.... Read more
Affected Products : fbx_software_development_kit- Published: Jan. 25, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-8935
IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to ... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-8948
IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more
Affected Products : emptoris_sourcing- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-2867
A design flaw in the Trane ComfortLink II SCC firmware version 2.0.2 service allows remote attackers to take complete control of the system.... Read more
Affected Products : comfortlink_ii_firmware- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2016-8774
The HIFI driver in Huawei Mate 8 phones with software versions before NXT-AL10C00B386, versions before NXT-CL00C92B386, versions before NXT-DL00C17B386, versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8763
The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an improper resource release vul... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8759
Video driver in Huawei P9 phones with software versions before EVA-AL10C00B192 and Huawei Honor 6 phones with software versions before H60-L02_6.10.1 has a stack overflow vulnerability, which allows attackers to crash the system or escalate user privilege... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6164
Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving sample size.... Read more
Affected Products : ffmpeg- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8426
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8419
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8422
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device co... Read more
Affected Products : android- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-8403
An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Modera... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8347
An issue was discovered in Kabona AB WebDatorCentral (WDC) application prior to Version 3.4.0. WDC does not limit authentication attempts that may allow a brute force attack method.... Read more
Affected Products : webdatorcentral- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-8329
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Mobile Application Platform). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated att... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-8310
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnera... Read more
Affected Products : flexcube_universal_banking- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025