Latest CVE Feed
-
9.0
CRITICALCVE-2016-4435
An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that t... Read more
- Published: May. 25, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-3083
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connection setup, the client in Apache Hive before 1.2.2 and 2.0.x before 2.0.1 doe... Read more
Affected Products : hive- Published: May. 30, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9924
In 1x in all Android releases from CAF using the Linux kernel, a Signed to Unsigned Conversion Error could potentially occur.... Read more
Affected Products : android- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9967
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9961
In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write protection.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-10364
With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.... Read more
Affected Products : kibana- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10756
XnView Classic for Windows Version 2.40 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .rle file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!RtlpR... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9898
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx+0x0000000000004cbb."... Read more
Affected Products : xnview- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9532
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX+0x0000000000001555."... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-7732
The Avira Mobile Security app before 1.5.11 for iOS sends sensitive login information in cleartext.... Read more
Affected Products : avira_mobile_security- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2015-7714
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action... Read more
Affected Products : realtyna_property_listing- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2805
An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-7668
Cross-site scripting (XSS) vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.3.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter.... Read more
Affected Products : easy2map- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16849
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.... Read more
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16777
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and exploit the suid sudo helper in order to escalate to root.... Read more
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1168
IBM Rational Engineering Lifecycle Manager 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credential... Read more
Affected Products : rational_engineering_lifecycle_manager- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17102
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].... Read more
Affected Products : fiyo_cms- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14184
An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each oth... Read more
- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17950
Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter.... Read more
Affected Products : blog- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11495
PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternatively, the attacker can leverage unauthenticated access to this script to trigger a reboot via an ifType=reb... Read more
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025