Latest CVE Feed
-
6.1
MEDIUMCVE-2017-9451
Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.... Read more
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9413
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authentication of users for requests that (1) subscribe to a podcast via the add parameter to podcastReceiverAdmin.vie... Read more
Affected Products : subsonic- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17572
FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.... Read more
Affected Products : amazon_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9298
Cross-site scripting vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to execute arbitrary JavaScript code.... Read more
Affected Products : device_manager- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9207
The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image, related to imagew-jpeg.c.... Read more
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9095
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.... Read more
Affected Products : diving_log- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9032
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) T1 or (2) tmLastConfigFileModifiedDate parameter to log_management.cgi.... Read more
Affected Products : serverprotect- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8939
The Warner Bros. ellentube app 3.1.1 through 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : ellentube- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8852
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted remote source. The problem is that the length of data written is an arbitrary number found within the file.... Read more
Affected Products : sapcar- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8208
The driver of honor 5C,honor 6x Huawei smart phones with software of versions earlier than NEM-AL10C00B356, versions earlier than Berlin-L21HNC432B360 have a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user ... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0476
A remote code execution vulnerability in AOSP Messaging could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution w... Read more
Affected Products : android- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0474
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution ... Read more
Affected Products : android- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8439
Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.... Read more
Affected Products : kibana- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8403
360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password. This affects firmware 2.1.4. Exploitation can... Read more
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8367
Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Easy MPEG to DVD Burner, Easy WMV/ASF/ASX to DVD Burner, Easy RM RMVB to DVD Burner, Easy CD DVD Copy, MP3/A... Read more
Affected Products : easy_avi\/divx\/xvid_to_dvd_burner easy_avi_divx_converter easy_cd_dvd_copy easy_dvd_creator easy_mov_converter easy_mpeg\/avi\/divx\/wmv\/rm_to_dvd easy_mpeg_to_dvd_burner easy_rm_rmvb_to_dvd_burner easy_video_to_3gp_converter easy_video_to_ipod\/mp4\/psp\/3gp_converter +8 more products- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8260
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to a type downcast, a value may improperly pass validation and cause an out of bounds write later.... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8257
In all Qualcomm products with Android releases from CAF using the Linux kernel, when accessing the sde_rotator debug interface for register reading with multiple processes, one process can free the debug buffer while another process still has the debug bu... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8236
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in an IPA driver.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-9606
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction with a lack of int... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6699
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a use... Read more
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025