Latest CVE Feed
-
8.8
HIGHCVE-2017-5218
A SQL Injection issue was discovered in SageCRM 7.x before 7.3 SP3. The AP_DocumentUI.asp web resource includes Utilityfuncs.js when the file is opened or viewed. This file crafts a SQL statement to identify the database that is to be in use with the curr... Read more
Affected Products : sagecrm- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-5226
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.... Read more
Affected Products : bubblewrap- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5359
EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.... Read more
Affected Products : sql_iplug- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5241
Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in the "Name" and "Description" fields of a Workspace, as well as the "Description" field of a File Details pane of a ... Read more
Affected Products : secure_file_transfer- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5368
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a maliciou... Read more
Affected Products : zoneminder- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5239
Due to a lack of standard encryption when transmitting sensitive information over the internet to a centralized monitoring service, the Eview EV-07S GPS Tracker discloses personally identifying information, such as GPS data and IMEI numbers, to any man-in... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5361
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, which makes it easier for remote attackers to obtain sensitive user password information via a timing side-c... Read more
Affected Products : request_tracker- Published: Jul. 03, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5236
Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.... Read more
Affected Products : appspider_pro- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5247
Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field. An authenticated user with permissions to upload or send files can populate this field with a filename that contains standard HTML scripting tags. The resulting scri... Read more
Affected Products : secure_file_transfer- Published: Jul. 18, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-5254
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5329
Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation.... Read more
Affected Products : terminal_services_agent- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5344
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist wer... Read more
Affected Products : dotcms- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5328
Palo Alto Networks Terminal Services Agent before 7.0.7 allows attackers to spoof arbitrary users via unspecified vectors.... Read more
Affected Products : terminal_services_agent- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5350
Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allow attackers to crash systemUI by leveraging incomplete exception handling. The Samsung ID is SVE-2016-7122.... Read more
Affected Products : samsung_mobile- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-5347
SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.... Read more
Affected Products : genixcms- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5364
Memory Corruption Vulnerability in Foxit PDF Toolkit v1.3 allows an attacker to cause Denial of Service and Remote Code Execution when the victim opens the specially crafted PDF file. The Vulnerability has been fixed in v2.0.... Read more
Affected Products : foxit_pdf_toolkit- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5372
The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system information by leveraging a missing authorization check for the (1) getInformation, (2) getParameters, (3) getServi... Read more
Affected Products : netweaver- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5356
Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5483
The SNMP parser in tcpdump before 4.9.0 has a buffer overflow in print-snmp.c:asn1_parse().... Read more
Affected Products : tcpdump- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5475
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.... Read more
Affected Products : serendipity- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025