Latest CVE Feed
-
9.3
HIGHCVE-2016-8479
An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device co... Read more
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8443
Possible unauthorized memory access in the hypervisor. Incorrect configuration provides access to subsystem page tables. Product: Android. Versions: Kernel 3.18. Android ID: A-32576499. References: QC-CR#964185.... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-5554
An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authentication. A physical attacker can press the "Volume Up" button during device boot,... Read more
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2016-9039
An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never free... Read more
Affected Products : smartos- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-3614
Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspecified vulnerability.... Read more
- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1002009
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function.... Read more
Affected Products : membership_simplified- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9878
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x00000... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1000226
Stop User Enumeration 1.3.8 allows user enumeration via the REST API... Read more
Affected Products : stop_user_enumeration- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1000221
In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access rest... Read more
Affected Products : opencast- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000194
October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.... Read more
Affected Products : october- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1000176
In SWFTools, a memcpy buffer overflow was found in swfc.... Read more
Affected Products : swftools- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1632
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more
Affected Products : sterling_file_gateway- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2013-0870
The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.... Read more
Affected Products : ffmpeg- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-6498
Alcatel-Lucent Home Device Manager before 4.1.10, 4.2.x before 4.2.2 allows remote attackers to spoof and make calls as target devices.... Read more
Affected Products : home_device_manager- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17065
An issue was discovered on D-Link DIR-605L Model B before FW2.11betaB06_hbrf devices, related to the code that handles the authentication values for HNAP. An attacker can cause a denial of service (device crash) or possibly have unspecified other impact b... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1000105
The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient.... Read more
Affected Products : blue_ocean- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-10289
An elevation of privilege vulnerability in the Qualcomm crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pr... Read more
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000078
Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration... Read more
Affected Products : onos- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000073
Creolabs Gravity version 1.0 is vulnerable to a heap overflow in an undisclosed component that can result in arbitrary code execution.... Read more
Affected Products : gravity- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1000062
kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution... Read more
Affected Products : kitto- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025