Latest CVE Feed
-
4.7
MEDIUMCVE-2017-10015
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Application Designer). Supported versions that are affected are 8.54 and 8.55. Difficult to exploit vulnerability allows low privileged attacker ... Read more
Affected Products : peoplesoft_enterprise_peopletools- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17713
Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp paramete... Read more
Affected Products : trape- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-12785
The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a buffer overflow in the "show log cli" command. This could be used by a read-only user (monitor role) to g... Read more
Affected Products : noviware- Published: Aug. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9037
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read may occur in the processing of a downlink 3G NAS message.... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9036
In all Qualcomm products with Android releases from CAF using the Linux kernel, an incorrect length is used to clear a memory buffer resulting in adjacent memory getting corrupted.... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9715
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a vendor command, a buffer over-read can occur.... Read more
Affected Products : android- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9683
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing a meta image, an integer overflow can occur, if user-defined image offset and size values are too large.... Read more
Affected Products : android- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15261
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Possible Stack Corruption starting at PDF!xmlGetGlobalState+0x000000... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12698
An Improper Authentication issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Specially crafted requests allow a possible authentication bypass that could allow remote code execution.... Read more
Affected Products : webaccess- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14283
XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000008fe4."... Read more
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12730
An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior. Application services utilize unquoted search path elements, which could allow an attacker to execute arbitrary code with elevated privileges.... Read more
Affected Products : mypro- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2014-0208
Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted key name.... Read more
Affected Products : foreman- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12359
A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (.arf) files could allow an attacker to execute arbitrary code on a system. An attacker could exploit this vulnerability by providing a user with a malic... Read more
Affected Products : webex_meeting_center webex_meetings_server webex_advanced_recording_format_player- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-12352
A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an authenticated, local attacker to gain elevated privileges and execute arbitrary commands with root privile... Read more
Affected Products : application_policy_infrastructure_controller- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2017-12350
A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local attacker to log in to an affected virtual appliance with root privileges. The vulnerability is due to the presence of default, static user ... Read more
Affected Products : umbrella_insights_virtual_appliance- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17631
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.... Read more
Affected Products : multireligion_responsive_matrimonial- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17622
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.... Read more
Affected Products : online_exam_test_application_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1223
IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL display... Read more
Affected Products : bigfix_platform- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12139
XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.... Read more
Affected Products : xoops- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8799
Untrusted input execution via igetwild in all iRODS versions before 4.1.11 and 4.2.1 allows other iRODS users (potentially anonymous) to execute remote shell commands via iRODS virtual pathnames. To exploit this vulnerability, a virtual iRODS pathname tha... Read more
Affected Products : irods- Published: May. 05, 2017
- Modified: Apr. 20, 2025