Latest CVE Feed
-
7.8
HIGHCVE-2017-6329
Symantec VIP Access for Desktop prior to 2.2.4 can be susceptible to a DLL Pre-Loading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on h... Read more
Affected Products : vip_access_for_desktop- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6403
An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password.... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6338
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or mod... Read more
Affected Products : interscan_web_security_virtual_appliance- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6349
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.... Read more
Affected Products : vim- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6443
Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1.... Read more
Affected Products : tmnet_webconfig- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6359
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.... Read more
Affected Products : qts- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-6346
Race condition in net/packet/af_packet.c in the Linux kernel before 4.9.13 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a multithreaded application that makes PACKET_FANOUT setsockopt syste... Read more
Affected Products : linux_kernel- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6400
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged command execution on NetBackup Server and Client can occur (on the local system).... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6360
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.... Read more
Affected Products : qts- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6370
TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.... Read more
Affected Products : typo3- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6394
Multiple Cross-Site Scripting (XSS) issues were discovered in OpenEMR 5.0.0 and 5.0.1-dev. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to the "openemr-master/gacl/admin/object_search.php" URL (section_value; src_f... Read more
Affected Products : openemr- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6379
Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker to disable some blocks on a site. This issue is mitigated by the fact that users would have to know the block ID.... Read more
Affected Products : drupal- Published: Mar. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6384
Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service. This is fixed in 7.2.8.... Read more
Affected Products : atheme- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6406
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6441
The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classificati... Read more
Affected Products : php- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6398
An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is root). Besides, the default installation of IMSVA comes ... Read more
Affected Products : interscan_messaging_security_virtual_appliance- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6480
groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).... Read more
Affected Products : cmsgroovel- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6397
An issue was discovered in FlightAirMap v1.0-beta.10. The vulnerability exists due to insufficient filtration of user-supplied data in multiple parameters passed to several *-sub-menu.php pages. An attacker could execute arbitrary HTML and script code in ... Read more
Affected Products : flightairmap- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6410
kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain ... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6405
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Hostname-based security is open to DNS spoofing.... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025