Latest CVE Feed
-
5.3
MEDIUMCVE-2017-4013
Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information via HTTP response header.... Read more
Affected Products : network_data_loss_prevention- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9030
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a directory traversal attack that bypasses a uniqid protection mechanism, and makes it easier to read arbitrary uploaded files.... Read more
Affected Products : b2j_contact- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-3882
A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote co... Read more
Affected Products : rv110w rv215w small_business_rv_router_firmware small_business_rv_router_firmware_1.0 rv132w rv134w rv042 rv042g rv320 rv325 +7 more products- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
7.9
HIGHCVE-2017-3873
A vulnerability in the Plug-and-Play (PnP) subsystem of the Cisco Aironet 1800, 2800, and 3800 Series Access Points running a Lightweight Access Point (AP) or Mobility Express image could allow an unauthenticated, adjacent attacker to execute arbitrary co... Read more
Affected Products : aironet_access_point_firmware aironet_access_point_software aironet_access_point_software aironet_1830e aironet_1830i aironet_1850e aironet_1850i aironet_2800e aironet_2800i aironet_3800e +2 more products- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6885
An error when handling certain external commands and services related to the FlexNet Inventory Agent and FlexNet Beacon of the Flexera Software FlexNet Manager Suite 2017 before 2017 R1 and 2014 R3 through 2016 R1 SP1 can be exploited to gain elevated pri... Read more
Affected Products : flexnet_manager_suite- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10239
In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper input validation an integer overflow vulnerability leading to a buffer overflow could potentially occur and a buffer ove... Read more
Affected Products : android- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10237
If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android releases from CAF using the Linux kernel, the TA would not detect an issue and it would be treated as secure memory... Read more
Affected Products : android- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-8998
In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.... Read more
Affected Products : android- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7953
INFOR EAM V11.0 Build 201410 has XSS via comment fields.... Read more
Affected Products : enterprise_asset_management- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8943
The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : pumatrac- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8942
The YottaMark ShopWell - Healthy Diet & Grocery Food Scanner app 5.3.7 through 5.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cert... Read more
Affected Products : shopwell_-_healthy_diet_\&_grocery_food_scanner- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8937
The Life Before Us Yo app 2.5.8 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : yo.- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8927
Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.... Read more
Affected Products : vizex_reader- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9595
The "First State Bank of Bigfork Mobile Banking" by First State Bank of Bigfork app 4.0.3 -- aka first-state-bank-of-bigfork-mobile-banking/id1133969876 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers ... Read more
Affected Products : first_state_bank_of_bigfork_mobile_banking- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9597
The "Blue Ridge Bank and Trust Co. Mobile Banking" by Blue Ridge Bank and Trust Co. app 3.0.1 -- aka blue-ridge-bank-and-trust-co-mobile-banking/id699679197 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attack... Read more
Affected Products : blue_ridge_bank_and_trust_co._mobile_banking- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-1000377
An issue was discovered in the size of the default stack guard page on PAX Linux (originally from GRSecurity but shipped by other Linux vendors), specifically the default stack guard page is not sufficiently large and can be "jumped" over (the stack guard... Read more
Affected Products : linux_kernel- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3743
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine,... Read more
- Published: Jun. 20, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-14141
The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.... Read more
Affected Products : kaltura_server- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-3419
vBulletin 5.x through 5.1.6 allows remote authenticated users to bypass authorization checks and inject private messages into conversations via vectors related to an input validation failure.... Read more
Affected Products : vbulletin- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-9616
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a request that redirects to the deny page.... Read more
Affected Products : netsweeper- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025