Latest CVE Feed
-
3.3
LOWCVE-2016-2567
secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by th... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2336
Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this assumed by developers can cause arbitrary code execution.... Read more
Affected Products : ruby- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6823
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.... Read more
Affected Products : fiyo_cms- Published: Mar. 12, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6781
A vulnerability in the management of shell user accounts for Cisco Policy Suite (CPS) Software for CPS appliances could allow an authenticated, local attacker to gain elevated privileges on an affected system. The affected privilege level is not at the ro... Read more
Affected Products : policy_suite- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6643
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Virtual Directory information on an affected system. The vulnerability exists because the affected soft... Read more
Affected Products : remote_expert_manager- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8589
log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6490
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (cid, value, element, mode, tab, form_name, id) passed to the EPESI-master/modules/Utils/RecordBrow... Read more
Affected Products : epesi- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6487
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (state, element, id, tab, cid) passed to the "EPESI-master/modules/Utils/RecordBrowser/favorites.ph... Read more
Affected Products : epesi- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6411
Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.... Read more
- Published: Mar. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6393
An issue was discovered in NagVis 1.9b12. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "nagvis-master/share/userfiles/gadgets/std_table.php" URL. An attacker could execute arbitrary HTML and script code in a ... Read more
Affected Products : nagvis- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8392
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8389
An exploitable integer-overflow vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will attempt to convert each character from a font into a polygon and then attempt to rasterize these shapes. As the applicatio... Read more
Affected Products : argus- Published: Feb. 28, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6186
Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full ... Read more
- Published: Mar. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-8230
In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.... Read more
Affected Products : lenovo_service_bridge- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6048
A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Success... Read more
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6078
FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with a crafted biSize field in the BITMAPINFOHEADER section.... Read more
Affected Products : maxview- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6023
An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215, CBE versions prior to V3.6 Build 170215, CM55E versions prior t... Read more
- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5881
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.... Read more
Affected Products : gom_player- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-5567
Code injection vulnerability in Avast Premier 12.3 (and earlier), Internet Security 12.3 (and earlier), Pro Antivirus 12.3 (and earlier), and Free Antivirus 12.3 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary... Read more
- Published: Mar. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6807
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent ... Read more
Affected Products : ambari- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025