Latest CVE Feed
-
7.6
HIGHCVE-2016-10289
An elevation of privilege vulnerability in the Qualcomm crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pr... Read more
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000078
Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration... Read more
Affected Products : onos- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000073
Creolabs Gravity version 1.0 is vulnerable to a heap overflow in an undisclosed component that can result in arbitrary code execution.... Read more
Affected Products : gravity- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1000062
kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution... Read more
Affected Products : kitto- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15992
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.... Read more
Affected Products : website_broker_script- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0806
An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62998805.... Read more
Affected Products : android- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0797
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-62459766. References: M-ALPS03353854.... Read more
Affected Products : android- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15921
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002010. This is due to the input buffer being NUL... Read more
- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-5613
Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving a file title, a different vulnerability than CVE-2015-5612.... Read more
Affected Products : october- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0598
An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to ... Read more
Affected Products : android- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0518
An elevation of privilege vulnerability in the Qualcomm fingerprint sensor driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a p... Read more
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0447
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pr... Read more
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15580
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .htm... Read more
Affected Products : osticket- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-5227
The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.... Read more
Affected Products : wordpress_landing_pages- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-2868
An exploitable remote code execution vulnerability exists in the Trane ComfortLink II firmware version 2.0.2 in DSS service. An attacker who can connect to the DSS service on the Trane ComfortLink II device can send an overly long REG request that can ove... Read more
Affected Products : comfortlink_ii_firmware- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15240
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x000000000... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14647
A heap-based buffer overflow was discovered in AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.... Read more
Affected Products : bento4- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14547
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .mobi file, related to a "Read Access Violation starting at STDUMOBIFile!DllUnregisterServer+0x000000000002efc0."... Read more
Affected Products : stdu_viewer- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9000
IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote attacker could exploit this vulnerability using a specially-crafted URL to navigate to a web page the attacker controls. An attacker c... Read more
Affected Products : infosphere_information_server infosphere_information_server_on_cloud infosphere_datastage- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9052
An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-based buffer overflow in the function as_sindex__simatch_by_iname resulting i... Read more
Affected Products : database_server- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025