Latest CVE Feed
-
7.5
HIGHCVE-2016-10185
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2016-6649
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface a... Read more
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10154
The smbhash function in fs/cifs/smbencrypt.c in the Linux kernel 4.9.x before 4.9.1 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspeci... Read more
Affected Products : linux_kernel- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6561
illumos smbsrv NULL pointer dereference allows system crash.... Read more
Affected Products : illumos- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6286
The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTP_PROXY environment variable, which would allow attackers to direct CGI programs which use this environment variable to use an attacker-specified HTTP proxy server (also kn... Read more
Affected Products : http-client- Published: Jan. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6240
Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large size value.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6234
The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file.... Read more
Affected Products : lepton- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-5899
IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
Affected Products : jazz_reporting_service- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2017-3625
Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server). Supported versions that are affected are 11.1.1.7, 11.1.1.9, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Easily "exploitable" vulnerability allows una... Read more
Affected Products : webcenter_content- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-3522
Vulnerability in the PeopleSoft Enterprise SCM eSupplier Connection component of Oracle PeopleSoft Products (subcomponent: Vendor). The supported version that is affected is 9.2. Easily "exploitable" vulnerability allows high privileged attacker with netw... Read more
Affected Products : peoplesoft_enterprise_scm_esupplier_connection- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3151
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.... Read more
Affected Products : atlas- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3110
Adobe Experience Manager 6.1 and earlier has a sensitive data exposure vulnerability.... Read more
Affected Products : experience_manager- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-5073
CloudView NMS before 2.10a has XSS via SNMP.... Read more
Affected Products : cloudview_nms- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5058
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.... Read more
Affected Products : lightify_pro- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-2865
An exploitable vulnerability exists in the firmware update functionality of Circle with Disney. Specially crafted network packets can cause the product to run an attacker-supplied shell script. An attacker can intercept and alter network traffic to trigge... Read more
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-4800
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to ba... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-8999
In TrustZone a buffer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel while loading an ELF file.... Read more
Affected Products : android- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2645
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.... Read more
Affected Products : moodle- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
6.7
MEDIUMCVE-2017-2723
The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of users' Safe passwords. An attacker with the root privilege of an Android system could forge the Safe to read users' plaintext Safe passwo... Read more
Affected Products : files- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-4337
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.... Read more
Affected Products : photostore- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025