Latest CVE Feed
-
7.5
HIGHCVE-2017-5681
The RSA-CRT implementation in the Intel QuickAssist Technology (QAT) Engine for OpenSSL versions prior to 0.5.19 may allow remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.... Read more
Affected Products : quickassist_technology_engine- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16881
b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL value to /settings/avatar, related to processor/AdminProcessor.java, processor/ArticleProcessor.java, processor/UserProcessor.java, se... Read more
Affected Products : symphony- Published: Nov. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16801
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.... Read more
Affected Products : octopus_deploy- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1678
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : rational_doors_next_generation- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16615
An exploitable vulnerability exists in the YAML parsing functionality in the parse_yaml_query method in parser.py in MLAlchemy before 0.2.2. When processing YAML-Based queries for data, a YAML parser can execute arbitrary Python commands resulting in comm... Read more
Affected Products : mlalchemy- Published: Nov. 08, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-16759
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.... Read more
Affected Products : librenms- Published: Nov. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16723
A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (runni... Read more
Affected Products : fl_comserver_basic_232_firmware fl_comserver_uni_422_firmware fl_comserver_bas_485-t_firmware fl_com_server_rs232_firmware fl_com_server_rs485_firmware psi-modem\/eth_firmware fl_comserver_basic_422_firmware fl_comserver_basic_485_firmware fl_comserver_uni_485-t_firmware fl_comserver_uni_485_firmware +16 more products- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5543
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.... Read more
Affected Products : subrion- Published: Jan. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16711
The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) because of extractDefini... Read more
Affected Products : swftools- Published: Nov. 09, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-5480
Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-office access to provide a .. (dot dot) in the fm_selected array parameter.... Read more
Affected Products : b2evolution- Published: Jan. 15, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-5228
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary ... Read more
Affected Products : metasploit- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-4987
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user can load a maliciously crafted file in the search path which may potentially allow the attacker to execute arbitrary code on th... Read more
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1613
IBM Connections 6.0 could allow an unauthenticated remote attacker to gain unauthenticated or unauthorized access to non-sensitive Engagement Center template data. IBM X-Force ID: 132954.... Read more
Affected Products : connections- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15959
Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576.... Read more
Affected Products : adultscriptpro- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-15884
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.... Read more
Affected Products : vagrant_vmware_fusion- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15813
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overflow can occur while reading firmware logs.... Read more
Affected Products : android- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15812
The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel.... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15802
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address con... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15801
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address con... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15786
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x00000000001a78db."... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025