Latest CVE Feed
-
5.3
MEDIUMCVE-2016-8271
Huawei eSpace IAD V300R002C01SPC100 and earlier versions have an information leak vulnerability; an attacker can check and download the fault information by accessing a special URL.... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-5698
Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmware version 11.6.x.1xxx which is vulnerable to CVE-2017-... Read more
- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5901
The State Bank of India State Bank Anywhere app 5.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : state_bank_anywhere- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5875
XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.... Read more
Affected Products : dotcms- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-7819
I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-1778
The custom authentication realm used by karaf-tomcat's "opendaylight" realm in Opendaylight before Helium SR3 will authenticate any username and password combination.... Read more
Affected Products : opendaylight- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2016-7815
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.... Read more
Affected Products : remote_service_manager- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-7809
Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows remote attackers to hijack the authentication of logged in user to conduct unintended operations via unspecified vectors.... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7783
SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-1529
Integer overflow in soundtrigger/ISoundTriggerHwService.cpp in Android allows attacks to cause a denial of service via unspecified vectors.... Read more
Affected Products : android- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-7477
The ff_put_pixels8_xy2_mmx function in rnd_template.c in Libav 11.7 allows remote attackers to cause a denial of service (invalid memory access and crash) via a crafted mp3 file. NOTE: this issue was originally reported as involving a NULL pointer derefe... Read more
Affected Products : libav- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-6791
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6785
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. ... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6247
OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6243
thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp parameter of the __thrsleep system call.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6239
The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6235
The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file.... Read more
Affected Products : lepton- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6123
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more
Affected Products : kenexa_lms_on_cloud- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-6100
IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz... Read more
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-6080
The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.... Read more
Affected Products : websphere_message_broker- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025