Latest CVE Feed
-
7.5
HIGHCVE-2017-11498
Buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to shut down the remote process (a denial of service) via a language pack (ZIP file) with invalid HTML ... Read more
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17895
Readymade Job Site Script has SQL Injection via the location_name array parameter to the /job URI.... Read more
Affected Products : basic_job_site_script- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11463
In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. In other words, a normal user can send requests to a spe... Read more
Affected Products : endpoint_manager- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-13772
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm... Read more
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12781
The EBML_BufferToID function in ebmlelement.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.... Read more
- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11018
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, array access out of bounds may occur in the camera driver in the kernel... Read more
Affected Products : android- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-16946
The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.... Read more
- Published: Nov. 25, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17774
admin/configuration.php in Piwigo 2.9.2 has CSRF.... Read more
Affected Products : piwigo- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-11348
In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in ... Read more
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-5170
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leve... Read more
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-5081
Cross-site request forgery (CSRF) vulnerability in django CMS before 3.0.14, 3.1.x before 3.1.1 allows remote attackers to manipulate privileged users into performing unknown actions via unspecified vectors.... Read more
Affected Products : django_cms- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11117
The ExifImageFile::readDHT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.... Read more
Affected Products : openexif- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2522
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreFoundation" component. It allows remote attac... Read more
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-10958
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11057
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in compatibility mode, flash_data from 64-bit userspace may cause disclosure of kernel memory or a fault due to using a userspace-provided addr... Read more
Affected Products : android- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11024
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in the rmnet USB control driver can potentially lead to a Use After Free condition.... Read more
Affected Products : android- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7909
A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept reques... Read more
- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10967
In FineCMS before 2017-07-06, application\core\controller\config.php allows XSS in the (1) key_name, (2) key_value, and (3) meaning parameters.... Read more
Affected Products : finecms- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-10829
Untrusted search path vulnerability in Remote Support Tool (Enkaku Support Tool) All versions distributed through the website till 2017 August 10 allow an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : enkaku_support_tool- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-4724
SQL injection vulnerability in Concrete5 5.7.3.1.... Read more
Affected Products : concrete_cms- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025