Latest CVE Feed
-
6.1
MEDIUMCVE-2017-11593
Cross-site scripting (XSS) vulnerability in the Markdown Preview Plus extension before 0.5.7 for Chrome allows remote attackers to inject arbitrary web script or HTML into some web applications via the upload and display of crafted text, markdown, or rst ... Read more
Affected Products : markdown_preview_plus- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11587
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is directory traversal in the filename parameter to the /download.conf URI.... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11584
dayrui FineCms 5.0.9 has SQL Injection via the field parameter in an action=module, action=member, action=form, or action=related request to libraries/Template.php.... Read more
Affected Products : finecms- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11522
The WriteOnePNGImage function in coders/png.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.... Read more
Affected Products : imagemagick- Published: Jul. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11469
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.... Read more
Affected Products : uptime_infrastructure_monitor- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11456
Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file.... Read more
- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1141
IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907.... Read more
Affected Products : insights_foundation_for_energy- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-11396
Vulnerability issues with the web service inspection of input parameters in Trend Micro Web Security Virtual Appliance 6.5 may allow potential attackers who already have administration rights to the console to implement remote code injections.... Read more
Affected Products : interscan_web_security_virtual_appliance- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11327
An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP resources such as admin/content.php and admin/content.php?method=ftp_upload.... Read more
Affected Products : tilde_cms- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1130
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select dialog boxes which would cause the client hang and have to be restarted. IBM X-Force ID: 121371.... Read more
- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
2.9
LOWCVE-2017-1124
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local attacker to obtain sensitive information using HTTP Header Injection. IBM Reference #: 1998053.... Read more
Affected Products : maximo_asset_management- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11194
Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter of adminservercacertdetails.cgi is reflected in the application's response and is not properly sanitized, allowing an attacker to inject... Read more
Affected Products : pulse_connect_secure- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11098
When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.... Read more
Affected Products : swftools- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11059
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different threads during SHA operations may potentially lead to a buffer overflow.... Read more
Affected Products : android- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11029
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, camera application triggers "user-memory-access" issue as the Camera CPP module Linux driver directly accesses the application provided buffer,... Read more
Affected Products : android- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1101
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
Affected Products : rational_quality_manager- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1100
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
Affected Products : rational_quality_manager- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-10418
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: PeopleSoft CDA). The supported version that is affected is 8.56. Easily exploitable vulnerability allows low privileged attacker with network ... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10991
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.... Read more
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-10892
Untrusted search path vulnerability in Music Center for PC version 1.0.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025