Latest CVE Feed
-
6.5
MEDIUMCVE-2017-3548
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker w... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.9
HIGHCVE-2017-3530
Vulnerability in the Oracle Transportation Manager component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0, 6.4.1 and 6.4.2. Easi... Read more
Affected Products : transportation_management- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
4.4
MEDIUMCVE-2016-3016
IBM Security Access Manager for Web processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code, which could allow an authenticated attacker to load malicious code.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-5642
Opmantek NMIS before 8.5.12G has XSS via SNMP.... Read more
Affected Products : network_management_information_system- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-3230
Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder). Supported versions that are affected are 11.1.1.9, 12.2.1.1 and 12.2.1.2. Easily "exploitable" vulnerability allows unauthenticated ... Read more
Affected Products : fusion_middleware_mapviewer- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-3218
Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.... Read more
Affected Products : magician- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3152
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.... Read more
Affected Products : atlas- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-1559
D-Link DAP-1353 H/W vers. B1 3.15 and earlier, D-Link DAP-2553 H/W ver. A1 1.31 and earlier, and D-Link DAP-3520 H/W ver. A1 1.16 and earlier reveal wireless passwords and administrative usernames and passwords over SNMP.... Read more
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-10702
Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's flash storage, and access an arbitrary application's JavaScript instance, by modifying a UUID value within the header of a crafted appl... Read more
- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10391
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length in an HCI command is not properly checked for validity.... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10399
Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remote attacker to read potentially sensitive system files via a specially crafted URL.... Read more
Affected Products : sendio- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-10280
An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p... Read more
Affected Products : android- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10177
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-13985
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclosure of information.... Read more
Affected Products : bsm_platform_application_performance_management_system_health- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2790
When processing a record type of 0x3c from a Workbook stream from an Excel file (.xls), JustSystems Ichitaro Office trusts that the size is greater than zero, subtracts one from the length, and uses this result as the size for a memcpy. This results in a ... Read more
Affected Products : ichitaro- Published: Feb. 24, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2015-0864
Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0554
An elevation of privilege vulnerability in the Telephony component could enable a local malicious application to access capabilities outside of its permission levels. This issue is rated as Moderate because it could be used to gain access to elevated capa... Read more
Affected Products : android- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
8.4
HIGHCVE-2017-3582
Vulnerability in the Oracle SuperCluster Specific Software component of Oracle Sun Systems Products Suite (subcomponent: Backup/Restore Utility). Supported versions that are affected are 2.3.8 and 2.3.13. Easily "exploitable" vulnerability allows unauthen... Read more
Affected Products : supercluster_specific_software- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-13670
In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonstrated by a ZIP archive that contains a .php file.... Read more
Affected Products : blackcat_cms- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-0355
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111894.... Read more
Affected Products : sametime- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025