Latest CVE Feed
-
9.8
CRITICALCVE-2017-6465
Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; however, it doesn't check the response's length, leading to a buffer overflow situation.... Read more
Affected Products : ftpshell_client- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6478
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).... Read more
Affected Products : mangoswebv4- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6472
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rtmpt.c by properly incrementing a certain sequence value.... Read more
- Published: Mar. 04, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6617
A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The v... Read more
Affected Products : integrated_management_controller_supervisor- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6481
Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (instructions in app/admin/instructions/preview.php; subnetId in app/admin/po... Read more
Affected Products : phpipam- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6501
An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could lead to a NULL pointer dereference.... Read more
Affected Products : imagemagick- Published: Mar. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6483
Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (lang_code in themes/*/admin/system_preferences/language_edit.tmpl.php). An ... Read more
Affected Products : atutor- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6509
Smith0r/burgundy-cms before 2017-03-06 is vulnerable to a reflected XSS in admin/components/menu/views/menuitems.php (id parameter).... Read more
Affected Products : burgundy-cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6503
WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.... Read more
Affected Products : qbittorrent- Published: Mar. 06, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6516
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system file... Read more
Affected Products : sysinfo- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6504
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.... Read more
Affected Products : qbittorrent- Published: Mar. 06, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6517
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to lo... Read more
Affected Products : skype- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6492
SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.... Read more
Affected Products : admidio- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6570
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id.... Read more
Affected Products : mail-masta- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6510
Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker to list and download any file from any folder outside the FTP root Directory.... Read more
Affected Products : easy_file_sharing_ftp_server- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6539
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, time) passed to the webpagetest-master/www/benchmarks/delta.php URL. An attacker coul... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6506
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.... Read more
Affected Products : data_expert_ultimate- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6591
There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field.... Read more
Affected Products : django-epiceditor- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-6520
The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potent... Read more
Affected Products : soundtouch_30- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6530
Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20 do not check password.shtml authorization, leading to Arbitrary password change.... Read more
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025