Latest CVE Feed
-
5.9
MEDIUMCVE-2017-5591
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.... Read more
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5608
Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script or HTML via a crafted image filename.... Read more
Affected Products : piwigo- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5616
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5600
The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.... Read more
Affected Products : oncommand_insight- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5689
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features g... Read more
Affected Products : active_management_technology_firmware simatic_field_pg_m5_firmware simatic_ipc427e_firmware simatic_ipc477e_firmware simatic_ipc547e_firmware simatic_ipc627d_firmware simatic_ipc647d_firmware simatic_ipc677d_firmware simatic_ipc827d_firmware simatic_ipc847d_firmware +61 more products- Actively Exploited
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-5607
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace... Read more
Affected Products : splunk- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5620
An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened in a new tab instead of getting downloaded. This creates an attack vector of executing code in the domain of the application.... Read more
Affected Products : zammad- Published: Mar. 13, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-5610
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5677
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.... Read more
Affected Products : html_ajax- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5632
An issue was discovered on the ASUS RT-N56U Wireless Router with Firmware 3.0.0.4.374_979. When executing an "nmap -O" command that specifies an IP address of an affected device, one can crash the device's WAN connection, causing disconnection from the In... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2017-5670
Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.... Read more
Affected Products : rios- Published: Apr. 04, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5628
An issue was discovered in Artifex Software, Inc. MuJS before 8f62ea10a0af68e56d5c00720523ebcba13c2e6a. The MakeDay function in jsdate.c does not validate the month, leading to an integer overflow when parsing a specially crafted JS file.... Read more
Affected Products : mujs- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.9
HIGHCVE-2017-5662
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable applica... Read more
Affected Products : batik- Published: Apr. 18, 2017
- Modified: Apr. 20, 2025
-
8.5
HIGHCVE-2017-5633
Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted re... Read more
- Published: Mar. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5635
In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the "anonymous" user.... Read more
Affected Products : nifi- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-5653
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.... Read more
Affected Products : cxf- Published: Apr. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5642
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.... Read more
Affected Products : ambari- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5717
Type Confusion in Content Protection HECI Service in Intel Graphics Driver allows unprivileged user to elevate privileges via local access.... Read more
Affected Products : graphics_driver- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5649
Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the data browser page in Pulse and consequently execute an ... Read more
Affected Products : geode- Published: Apr. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5654
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthorized read access to files on the host where the Ambari server executes.... Read more
Affected Products : ambari- Published: May. 12, 2017
- Modified: Apr. 20, 2025