Latest CVE Feed
-
4.9
MEDIUMCVE-2017-3477
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 12.0.0 and 12.1.0. Difficult to exploit vulnerability allows low privileged at... Read more
Affected Products : flexcube_private_banking- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14681
The daemon in P3Scan 3.0_rc1 and earlier creates a p3scan.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for p3scan.pid modification before ... Read more
Affected Products : p3scan- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14627
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the... Read more
Affected Products : labelprint- Published: Sep. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14581
The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of service (service crash) via a crafted request, aka SAP Security Note 2389181.... Read more
Affected Products : netweaver_application_server_java- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1444
IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus... Read more
Affected Products : emptoris_sourcing- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3196
PCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory outside of its typical bounds on the driver's receipt of network packets. Local attackers can exploit this issue to exe... Read more
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14425
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/etc/hnapasswd permissions.... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14414
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/shareport.php.... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14402
The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT CREATION" section, related to lack of input validation in include/function.php.... Read more
Affected Products : eyesofnetwork- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-14337
When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate authentication and this API returns an empty value, the... Read more
Affected Products : misp- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14288
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllGetClassObject+0x0000000000002ff7."... Read more
Affected Products : stdu_viewer- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16691
SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note file of type 'SAR'. The digital signature verification is done together with the extraction of note file ... Read more
Affected Products : business_application_software_integrated_solution- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16679
URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.52, that allows an attacker to redirect use... Read more
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16636
In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located in the new page, new category, and edit post function body message context. Remote attackers are able to bypass the basic editor validation to trigger cross site scripting. The XSS is persistent... Read more
Affected Products : bludit- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16568
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, which become permanently stored on the server and execute... Read more
Affected Products : media_server- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16564
Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject arbitrary web script or HTML via the DHCP vendor class ID field (P148).... Read more
- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16359
In radare 2.0.1, a pointer wraparound vulnerability exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c.... Read more
Affected Products : radare2- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15990
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.... Read more
Affected Products : phpinventory- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15962
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.... Read more
Affected Products : istock_management_system- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-15949
Xavier PHP Management Panel 2.4 allows SQL injection via the usertoedit parameter to admin/adminuseredit.php or the log_id parameter to admin/editgroup.php.... Read more
Affected Products : xavier- Published: Oct. 28, 2017
- Modified: Apr. 20, 2025