Latest CVE Feed
-
7.6
HIGHCVE-2016-8480
An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first re... Read more
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8420
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2016-6092
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2016-8942
IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6030
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
Affected Products : rational_collaborative_lifecycle_management- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2016-0394
IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-6604
NULL pointer dereference in Samsung Exynos fimg2d driver for Android L(5.0/5.1) and M(6.0) allows attackers to have unspecified impact via unknown vectors. The Samsung ID is SVE-2016-6382.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6077
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.... Read more
- Actively Exploited
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5585
OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allows remote authenticated users to con... Read more
Affected Products : documentum_content_server- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-9684
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component responsible for p... Read more
Affected Products : sonicwall_secure_remote_access_server- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-3837
An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allow an authenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of con... Read more
Affected Products : meeting_server- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6056
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a C... Read more
- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-8968
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IB... Read more
Affected Products : rational_collaborative_lifecycle_management- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5141
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invalidating any existing session identifier, which gives the ... Read more
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2016-8377
An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vulnerability exists when the software application connects to a malicious server, resulting in a stack buffer overflow. This causes an ex... Read more
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8709
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a speci... Read more
Affected Products : nitro_pdf_pro- Published: Feb. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5941
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Express... Read more
Affected Products : node-serialize- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6803
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin passwor... Read more
Affected Products : ftp_voyager- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-8708
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.... Read more
Affected Products : pluck- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6366
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dnslook... Read more
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025