Latest CVE Feed
-
9.8
CRITICALCVE-2017-9980
In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command injection, via the "pip" parameter.... Read more
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9979
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can ... Read more
Affected Products : quantastor- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9945
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast. The affected component requ... Read more
- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9900
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx!gffGetFormatInfo+0x000000000002e385."... Read more
Affected Products : xnview- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9896
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at Xfpx!gffGetFormatInfo+0x0000000000013e8a."... Read more
Affected Products : xnview- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9811
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). By abusing the quarantine read and write operations, it is possible to elevate the pr... Read more
Affected Products : anti-virus_for_linux_server- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9797
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In additi... Read more
Affected Products : geode- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9365
CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false. A page with id=1 can be unlocked.... Read more
Affected Products : bigtree_cms- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9710
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, IOCTL interface to send QMI NOTIFY REQ messages can be called from multiple contexts which can result in buffer overflow of msg cache.... Read more
Affected Products : android- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9615
Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging writes the administrator password to a world-readable file.... Read more
Affected Products : moneyworks- Published: Jun. 26, 2017
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-9493
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to conduct successful forced-pairing attacks (between an RF4CE remote and a set-top box) by repeatedly transmitting the same pairing code... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17574
FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.... Read more
Affected Products : care_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17573
FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id parameter.... Read more
Affected Products : ebay_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-9355
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file.... Read more
Affected Products : subsonic- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-9339
A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.... Read more
Affected Products : owncloud- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9332
The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag.... Read more
Affected Products : pivotx- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9272
The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack.... Read more
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-8879
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.... Read more
Affected Products : dolibarr_erp\/crm- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8876
Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8863
Information disclosure of .esp source code on the Cohu 3960 allows an attacker to view sensitive information such as application logic with a simple web browser.... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025