Latest CVE Feed
-
9.3
HIGHCVE-2017-6549
Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, ... Read more
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6560
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack.... Read more
Affected Products : agora-project- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6553
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon.... Read more
Affected Products : privilege_manager_for_unix- Published: Apr. 29, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6712
A vulnerability in certain commands of Cisco Elastic Services Controller could allow an authenticated, remote attacker to elevate privileges to root and run dangerous commands on the server. The vulnerability occurs because a "tomcat" user on the system c... Read more
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6561
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack.... Read more
Affected Products : agora-project- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6562
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack.... Read more
Affected Products : agora-project- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6589
EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.... Read more
Affected Products : epiceditor- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6574
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: filter_list.... Read more
Affected Products : mail-masta- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6577
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: list_id.... Read more
Affected Products : mail-masta- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6596
partclone.chkimg in partclone 0.2.89 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to launch a 'Denial of Service attack' in the context of the user running the... Read more
Affected Products : partclone- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6594
The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.... Read more
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-6612
A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. More Information... Read more
Affected Products : asr_5000_series_software- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6605
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a reflective cross-site scripting (XSS) attack against a user of the web-based management interface of a... Read more
Affected Products : identity_services_engine- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6619
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software does not... Read more
Affected Products : integrated_management_controller_supervisor- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-6608
A vulnerability in the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper parsing of craft... Read more
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6629
A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attacker to access files in arbitrary locations on the filesystem of an affected device. The issue is due to improper sanitization of user-su... Read more
Affected Products : unity_connection- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6683
A vulnerability in the esc_listener.py script of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to execute arbitrary commands as the tomcat user on an affected system, aka an Authentication Request Processing Arbitrary Co... Read more
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
7.7
HIGHCVE-2017-6609
A vulnerability in the IPsec code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload of the affected system. The vulnerability is due to improper parsing of malformed IPsec packets. An attacker could exploit this vulnera... Read more
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-6614
A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authenticated, remote attacker to download and view any system file by using the affected software. The vulnerability is du... Read more
Affected Products : findit_network_probe- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-6620
A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability is due to incorrect implementation... Read more
- Published: May. 03, 2017
- Modified: Apr. 20, 2025