Latest CVE Feed
-
6.8
MEDIUMCVE-2017-8371
Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : struxureware_data_center_expert- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8297
A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole "Simple PHP File Manager" component).... Read more
Affected Products : simple-file-manager- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8279
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, missing race condition protection while updating msg mask table can lead to buffer over-read. Also access to freed memory can happen while upda... Read more
Affected Products : android- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8268
In all Qualcomm products with Android releases from CAF using the Linux kernel, the camera application can possibly request frame/command buffer processing with invalid values leading to the driver performing a heap buffer over-read.... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8242
In all Android releases from CAF using the Linux kernel, a race condition exists in a QTEE driver potentially leading to an arbitrary memory write.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8033
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268. A filesystem traversal vulnerability exists in the Cloud Controller that allows a space developer... Read more
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8224
Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET.... Read more
- Published: Apr. 25, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8212
The driver of honor 5C,honor 6x Huawei smart phones with software of versions earlier than NEM-AL10C00B356, versions earlier than Berlin-L21HNC432B360 have a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user ... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8210
The driver of honor 5C,honor 6x Huawei smart phones with software of versions earlier than NEM-AL10C00B356, versions earlier than Berlin-L21HNC432B360 have a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user ... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8157
OceanStor 5800 V3 with software V300R002C00 and V300R002C10, OceanStor 6900 V3 V300R001C00 has an information leakage vulnerability. Products use TLS1.0 to encrypt. Attackers can exploit TLS1.0's vulnerabilities to decrypt data to obtain sensitive informa... Read more
Affected Products : oceanstor_5800_v3_firmware oceanstor_6900_v3_firmware oceanstor_5800_v3 oceanstor_6900_v3- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8134
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privi... Read more
Affected Products : fusionsphere_openstack- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
2.3
LOWCVE-2017-8118
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.... Read more
Affected Products : uma- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8018
EMC AppSync host plug-in versions 3.5 and below (Windows platform only) includes a denial of service (DoS) vulnerability that could potentially be exploited by malicious users to compromise the affected system.... Read more
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7991
Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.... Read more
Affected Products : exponent_cms- Published: Apr. 22, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-7930
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws with the potential to expose change records in the clear and allow a malicious party to spoof a server wit... Read more
Affected Products : pi_data_archive- Published: Aug. 25, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7881
BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modul... Read more
Affected Products : bigtree_cms- Published: Apr. 15, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7684
Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files to the server.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-7571
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.... Read more
Affected Products : faveo_helpdesk- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7564
In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors involving debug exceptions and debug registers.... Read more
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7455
Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.... Read more
Affected Products : mxview- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025