Latest CVE Feed
-
7.8
HIGHCVE-2017-13779
GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions. This allows local users to gain privileges by replacing... Read more
Affected Products : india_goods_and_services_tax_network_offline_utility_tool- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1372
IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosu... Read more
Affected Products : tririga_application_platform- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-1370
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.... Read more
Affected Products : jazz_reporting_service- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-13697
controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.... Read more
Affected Products : finecms- Published: Aug. 25, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1338
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9020
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the unlocking of memory.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9007
In TrustZone in all Android releases from CAF using the Linux kernel, a Double Free vulnerability could potentially exist.... Read more
Affected Products : android- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-13157
An information disclosure vulnerability in the Android system (activitymanagerservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-32990341.... Read more
Affected Products : android- Published: Dec. 06, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2017-1304
IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing of an unsupported configuration, where users applications are running on an active ESS I/O server node an... Read more
Affected Products : elastic_storage_server- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12802
The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.... Read more
- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-1847
Directory traversal vulnerability in the web request/response interface in Appserver before 1.0.3 allows remote attackers to read normally inaccessible files via a .. (dot dot) in a crafted URL.... Read more
Affected Products : appserver- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1292
IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153.... Read more
Affected Products : maximo_application_suite maximo_asset_management maximo_asset_management_essentials- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12821
Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 might cause remote code execution.... Read more
Affected Products : sentinel_ldk_rte_firmware- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12779
The Node_GetData function in corec/corec/node/node.c in mkvalidator 0.5.1 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.... Read more
Affected Products : mkvalidator- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12631
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3 and Spring 4 plugins in versions before 1.4.3 an... Read more
Affected Products : cxf_fediz- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12589
ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.... Read more
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1258
IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685... Read more
Affected Products : security_guardium- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1249
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12343
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client ... Read more
Affected Products : data_center_network_manager- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1234
IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
Affected Products : qradar_security_information_and_event_manager- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025