Latest CVE Feed
-
10.0
HIGHCVE-2017-9479
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitrary commands as root by leveraging local network access and connecting to the syseventd server, as demonst... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9204
The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted image, related to imagew-jpeg.c.... Read more
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-9139
There is a stack-based buffer overflow on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). Crafted POST requests to an unspecified URL result in DoS, interrupting the HTTP service (used to login to the web UI of a router) for 1 to 2 seco... Read more
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0863
An elevation of privilege vulnerability in the Upstream kernel video driver. Product: Android. Versions: Android kernel. Android ID: A-37950620.... Read more
Affected Products : android- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8864
Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to the camera and cause malfunction or code execution, as demonstrated by a client-side "if (!passwordsAreEqual())" t... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8199
MAX PRESENCE V100R001C00, TP3106 V100R002C00, TP3206 V100R002C00 have an out-of-bounds read vulnerability in H323 protocol. An attacker logs in to the system as a user and send crafted packets to the affected products. Due to insufficient verification of ... Read more
Affected Products : tp3106_firmware max_presence_firmware tp3206_firmware tp3106 max_presence tp3206- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-3149
Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : clickshare_csm-1_firmware clickshare_csc-1_firmware clickshare_csc-1 clickshare_csm-1- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-1914
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevi... Read more
Affected Products : blackberry_enterprise_service- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-7055
There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and ... Read more
- Published: May. 04, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-10135
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulnerabili... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-10333
Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: EAI). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11777
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how Sha... Read more
Affected Products : sharepoint_enterprise_server- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12896
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_server_aus tcpdump- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
5.1
MEDIUMCVE-2017-17556
A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by modifying registry keys.... Read more
Affected Products : synaptics_touchpad_driver- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2017-3325
Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: EAI). The supported version that is affected is 16.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel... Read more
Affected Products : siebel_ui_framework- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2017-5042
Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe a... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5664
The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwarded to the error page. This means that the request is p... Read more
Affected Products : tomcat- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8356
In ImageMagick 7.0.5-5, the ReadSUNImage function in sun.c allows attackers to cause a denial of service (memory leak) via a crafted file.... Read more
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-8580
Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fail... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8929
The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule.... Read more
Affected Products : yara- Published: May. 14, 2017
- Modified: Apr. 20, 2025