Latest CVE Feed
-
6.2
MEDIUMCVE-2017-2330
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbit virus, or wabbit, which will crea... Read more
Affected Products : northstar_controller- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-2321
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modificatio... Read more
Affected Products : northstar_controller- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-4895
Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9518
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.... Read more
Affected Products : atmail- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-2192
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own.... Read more
Affected Products : pl\/java- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9250
The lexer_process_char_literal function in jerry-core/parser/js/js-lexer.c in JerryScript 1.0 does not skip memory allocation for empty strings, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) vi... Read more
Affected Products : jerryscript- Published: May. 28, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-6703
A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack another user's session. More Information: CSCvc90346. Known Affected Releases: 12.1.... Read more
Affected Products : prime_collaboration_provisioning- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-3400
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.... Read more
Affected Products : data_ontap- Published: Jul. 03, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-2782
An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To ... Read more
Affected Products : matrixssl- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-4981
EMC RSA BSAFE Cert-C before 2.9.0.5 contains a potential improper certificate processing vulnerability.... Read more
Affected Products : bsafe_cert-c- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14142
Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) partnerId or (2) playerVersion parameter to server/admin_console/web/tools/bigRedButton.php; the (3) par... Read more
Affected Products : kaltura_server- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14270
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at ntdll_77400000!RtlFillMemoryUlong+0x0000000000000010."... Read more
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14492
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.... Read more
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14349
An authentication vulnerability in HPE SiteScope product versions 11.2x and 11.3x, allows read-only accounts to view all SiteScope interfaces and monitors, potentially exposing sensitive data.... Read more
Affected Products : sitescope- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14734
The build_msps function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted BPG file, related to hevc_decode_init1.... Read more
Affected Products : libbpg- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9551
Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr_registration table. The values are... Read more
Affected Products : mahara- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14078
SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.... Read more
Affected Products : mobile_security- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12252
A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to device availability, confidentiality, and integrity. The vulnerability i... Read more
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-3890
Use-after-free vulnerability in Open Litespeed before 1.3.10.... Read more
Affected Products : openlitespeed- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2014-3702
Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denial of service (resource consumption) via a .. (dot dot) the session parameter.... Read more
Affected Products : edeploy- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025