Latest CVE Feed
-
7.8
HIGHCVE-2017-3584
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: RAS subsystems). The supported version that is affected is AK 2013. Difficult to exploit vulnerability allows low privileged attacker wit... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-5811
An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. User controlled input is not neutralized prior to being placed in web page output (CROSS-SITE SCRIPTING).... Read more
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-3535
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2 and 12.0.3. Easily "exploitable" vulnerabili... Read more
Affected Products : flexcube_universal_banking- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5754
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.... Read more
Affected Products : access_manager- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
8.5
HIGHCVE-2017-3493
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.0 and 12.1.0. Easily "exploitable" vulnerabi... Read more
Affected Products : flexcube_enterprise_limits_and_collateral_management- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-3485
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Difficul... Read more
Affected Products : flexcube_universal_banking- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-3245
Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Pre-Login). Supported versions that are affected are 12.0.2 and 12.0.3. Easily exploitable vulnerability allows unauthenticated attacker... Read more
Affected Products : flexcube_direct_banking- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-5059
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/var/mobile/Containers/Data/Application.... Read more
Affected Products : lightify_pro- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-5055
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.... Read more
Affected Products : lightify_pro- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6042
IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of objects in memory. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability ... Read more
Affected Products : security_appscan- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4928
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.... Read more
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
9.0
CRITICALCVE-2017-2882
An exploitable vulnerability exists in the servers update functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause the device to overwrite sensitive files, resulting in code execution. An attacker needs to im... Read more
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-4894
SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors.... Read more
Affected Products : setucocms- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4887
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.... Read more
Affected Products : basercms- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2809
An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger th... Read more
Affected Products : ansible-vault- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2781
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. To tr... Read more
Affected Products : matrixssl- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-4832
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.... Read more
Affected Products : waon- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9003
In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.... Read more
Affected Products : android- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2729
The boot loaders in Honor 5A smart phones with software Versions earlier than CAM-TL00C01B193,Versions earlier than CAM-TL00HC00B193,Versions earlier than CAM-UL00C00B193 have a buffer overflow vulnerability. An attacker with the root privilege of an Andr... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2719
FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the insufficient input validation on one port. An attacker can exploit the vulnerabilities to gain root privileges by sending some message... Read more
Affected Products : fusionsphere_openstack- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025