Latest CVE Feed
-
10.0
HIGHCVE-2017-8011
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with defa... Read more
Affected Products : emc_m\&r emc_storage_monitoring_and_reporting emc_vipr_srm emc_vnx_monitoring_and_reporting- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10067
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multipl... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-10018
Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Strategic Sourcing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access ... Read more
Affected Products : peoplesoft_enterprise_scm_strategic_sourcing- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9801
When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP headers.... Read more
Affected Products : commons_email- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2014-0141
Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.... Read more
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-5224
The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.... Read more
Affected Products : util-linux- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2015-4071
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}.... Read more
Affected Products : helpdesk_pro- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6762
An elevation of privilege vulnerability in the libziparchive library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access... Read more
Affected Products : android- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-10125
D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a hardcoded SSL private key, which allows man-in-the-middle attackers to spoof devices by hijacking an HTTPS session.... Read more
Affected Products : dgs-1100_firmware dgs-1100-05 dgs-1100-05pd dgs-1100-08 dgs-1100-08p dgs-1100-10mp dgs-1100-10mpp dgs-1100-16 dgs-1100-18 dgs-1100-24 +3 more products- Published: Jan. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4298
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate space for a list of elements using a length from the file. When calculating this length, an integer overflow can be mad... Read more
Affected Products : hancom_office_2014- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2015-2943
Honda Moto LINC 1.6.1 does not verify SSL certificates.... Read more
Affected Products : moto_linc- Published: Sep. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2822
An exploitable code execution vulnerability exists in the image rendering functionality of Lexmark Perceptive Document Filters 11.3.0.2400. A specifically crafted PDF can cause a function call on a corrupted DCTStream to occur, resulting in user controlle... Read more
Affected Products : perceptive_document_filters- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-2975
IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : sametime- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-2972
IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.... Read more
Affected Products : sametime- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-2971
IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. IBM X-Force ID: 113898.... Read more
Affected Products : sametime- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-0765
Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.... Read more
Affected Products : eshop_plugin- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0398
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Produc... Read more
Affected Products : android- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-3151
Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attacker... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-8398
Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. References: QC-CR#877705.... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8480
An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first re... Read more
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025