Latest CVE Feed
-
7.5
HIGHCVE-2017-6474
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating record sizes.... Read more
- Published: Mar. 04, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6459
The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via vectors related to an argument with multiple null bytes.... Read more
Affected Products : ntp- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6465
Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; however, it doesn't check the response's length, leading to a buffer overflow situation.... Read more
Affected Products : ftpshell_client- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6478
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).... Read more
Affected Products : mangoswebv4- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6472
In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rtmpt.c by properly incrementing a certain sequence value.... Read more
- Published: Mar. 04, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6617
A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The v... Read more
Affected Products : integrated_management_controller_supervisor- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6481
Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (instructions in app/admin/instructions/preview.php; subnetId in app/admin/po... Read more
Affected Products : phpipam- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6501
An issue was discovered in ImageMagick 6.9.7. A specially crafted xcf file could lead to a NULL pointer dereference.... Read more
Affected Products : imagemagick- Published: Mar. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6483
Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (lang_code in themes/*/admin/system_preferences/language_edit.tmpl.php). An ... Read more
Affected Products : atutor- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6509
Smith0r/burgundy-cms before 2017-03-06 is vulnerable to a reflected XSS in admin/components/menu/views/menuitems.php (id parameter).... Read more
Affected Products : burgundy-cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6503
WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.... Read more
Affected Products : qbittorrent- Published: Mar. 06, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6516
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system file... Read more
Affected Products : sysinfo- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6504
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.... Read more
Affected Products : qbittorrent- Published: Mar. 06, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6517
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to lo... Read more
Affected Products : skype- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6492
SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.... Read more
Affected Products : admidio- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6570
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id.... Read more
Affected Products : mail-masta- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6510
Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker to list and download any file from any folder outside the FTP root Directory.... Read more
Affected Products : easy_file_sharing_ftp_server- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6539
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, time) passed to the webpagetest-master/www/benchmarks/delta.php URL. An attacker coul... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6506
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.... Read more
Affected Products : data_expert_ultimate- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6591
There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field.... Read more
Affected Products : django-epiceditor- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025