Latest CVE Feed
-
4.7
MEDIUMCVE-2016-10295
An information disclosure vulnerability in the Qualcomm LED driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pro... Read more
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10292
A denial of service vulnerability in the Qualcomm Wi-Fi driver could enable a proximate attacker to cause a denial of service in the Wi-Fi subsystem. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Version... Read more
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-10291
An elevation of privilege vulnerability in the Qualcomm Slimbus driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p... Read more
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15384
rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action.... Read more
Affected Products : rate_me- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-1527
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Fo... Read more
Affected Products : business_process_manager- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15213
Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_name or email_address field to themes/CleanFS/templates/common.editallusers.tpl.... Read more
Affected Products : flyspray- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-3883
Multiple cross-site scripting (XSS) vulnerabilities in qdPM 8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) search[keywords] parameter to index.php/users page; the (2) "Name of application" on index.php/configuration; (3) a n... Read more
Affected Products : qdpm- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15084
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.... Read more
Affected Products : metasploit- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15035
EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).... Read more
Affected Products : pyrobatchftp- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1502
IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo... Read more
Affected Products : content_navigator- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-14983
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the object parameter to module/admin_conf/index.php.... Read more
Affected Products : eyesofnetwork- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14920
Stored XSS vulnerability in eGroupware Community Edition before 16.1.20170922 allows an unauthenticated remote attacker to inject JavaScript via the User-Agent HTTP header, which is mishandled during rendering by the application administrator.... Read more
Affected Products : egroupware- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14904
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a crafted binder request can cause an arbitrary unmap in MediaServer.... Read more
Affected Products : android- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14795
The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a crafted BPG file, related to improper interaction wit... Read more
Affected Products : libbpg- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14703
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.... Read more
Affected Products : cash_back_comparison- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-3198
The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL.... Read more
Affected Products : jboss_wildfly_application_server- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-3188
The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : storm- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1460
IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14570
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64LdrpInitialize+0x00000000000008e1."... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14427
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/run/storage_account_root permissions.... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025