Latest CVE Feed
-
7.6
HIGHCVE-2015-8996
In TrustZone a time-of-check time-of-use race condition could potentially exist in a QFPROM routine in all Android releases from CAF using the Linux kernel.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-13173
An elevation of privilege vulnerability in the MediaTek system server. Product: Android. Versions: Android kernel. Android ID A-28067350. References: M-ALPS02672361.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Dec. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-13157
An information disclosure vulnerability in the Android system (activitymanagerservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-32990341.... Read more
Affected Products : android- EPSS Score: %0.11
- Published: Dec. 06, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2017-1304
IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing of an unsupported configuration, where users applications are running on an active ESS I/O server node an... Read more
Affected Products : elastic_storage_server- EPSS Score: %0.07
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12802
The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.... Read more
- EPSS Score: %0.68
- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12971
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.... Read more
Affected Products : apache2triad- EPSS Score: %2.53
- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-1847
Directory traversal vulnerability in the web request/response interface in Appserver before 1.0.3 allows remote attackers to read normally inaccessible files via a .. (dot dot) in a crafted URL.... Read more
Affected Products : appserver- EPSS Score: %0.38
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1292
IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153.... Read more
Affected Products : maximo_application_suite maximo_asset_management maximo_asset_management_essentials- EPSS Score: %0.18
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12821
Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 might cause remote code execution.... Read more
Affected Products : sentinel_ldk_rte_firmware- EPSS Score: %3.00
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12779
The Node_GetData function in corec/corec/node/node.c in mkvalidator 0.5.1 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.... Read more
Affected Products : mkvalidator- EPSS Score: %0.46
- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12728
An Improper Privilege Management issue was discovered in SpiderControl SCADA Web Server Version 2.02.0007 and prior. Authenticated, non-administrative local users are able to alter service executables with escalated privileges, which could allow an attack... Read more
Affected Products : scada_webserver- EPSS Score: %0.05
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12706
A stack-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying... Read more
Affected Products : webaccess- EPSS Score: %1.36
- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12649
XSS exists in Liferay Portal before 7.0 CE GA4 via a crafted title or summary that is mishandled in the Web Content Display.... Read more
Affected Products : liferay_portal- EPSS Score: %0.25
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12631
Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3 and Spring 4 plugins in versions before 1.4.3 an... Read more
Affected Products : cxf_fediz- EPSS Score: %1.37
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-8322
NetApp OnCommand System Manager 8.3.x before 8.3.2 allows remote authenticated users to execute arbitrary code via unspecified vectors.... Read more
Affected Products : data_ontap- EPSS Score: %2.42
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12621
During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser instantiation the parser will attempt to connect to said URL.... Read more
Affected Products : commons_jelly- EPSS Score: %0.46
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12589
ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.... Read more
- EPSS Score: %0.16
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1258
IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685... Read more
Affected Products : security_guardium- EPSS Score: %0.18
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1249
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more
- EPSS Score: %0.20
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12343
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client ... Read more
Affected Products : data_center_network_manager- EPSS Score: %0.91
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025