Latest CVE Feed
-
5.5
MEDIUMCVE-2017-6078
FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with a crafted biSize field in the BITMAPINFOHEADER section.... Read more
Affected Products : maxview- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6023
An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215, CBE versions prior to V3.6 Build 170215, CM55E versions prior t... Read more
- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5881
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.... Read more
Affected Products : gom_player- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-5567
Code injection vulnerability in Avast Premier 12.3 (and earlier), Internet Security 12.3 (and earlier), Pro Antivirus 12.3 (and earlier), and Free Antivirus 12.3 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary... Read more
- Published: Mar. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6807
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent ... Read more
Affected Products : ambari- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5257
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert XSS strings in certain SNMP OIDs which will execute in the context of the currently-logged on user.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5233
Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.... Read more
Affected Products : appspider_pro- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5004
EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Stored Cross Site S... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-4964
Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the director, aka a "CPI code injection vulnerability."... Read more
Affected Products : bosh_azure_cpi- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-4961
An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on t... Read more
Affected Products : bosh- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-4897
VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. ... Read more
Affected Products : horizon_daas- Published: May. 31, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10392
In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel memory.... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10386
In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10334
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-0073
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers,... Read more
- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10297
In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.... Read more
Affected Products : android- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2014-0043
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is ... Read more
Affected Products : wicket- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10181
An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6601
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.... Read more
Affected Products : webnms_framework- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-3812
A vulnerability in the implementation of Common Industrial Protocol (CIP) functionality in Cisco Industrial Ethernet 2000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to a system memory l... Read more
Affected Products : industrial_ethernet_2000_series_firmware industrial_ethernet_2000_series_firmware industrial_ethernet_2000_16ptc-g-e_switch industrial_ethernet_2000_16ptc-g-l_switch industrial_ethernet_2000_16ptc-g-nx_switch industrial_ethernet_2000_16t67-b_switch industrial_ethernet_2000_16t67p-g-e_switch industrial_ethernet_2000_16tc-g-e_switch industrial_ethernet_2000_16tc-g-l_switch industrial_ethernet_2000_16tc-g-n_switch +21 more products- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025