Latest CVE Feed
-
7.8
HIGHCVE-2017-3166
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable lo... Read more
Affected Products : hadoop- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3150
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.... Read more
Affected Products : atlas- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-3134
An escalation of privilege vulnerability in Fortinet FortiWLC-SD versions 8.2.4 and below allows attacker to gain root access via the CLI command 'copy running-config'.... Read more
Affected Products : fortiwlc-sd- Published: May. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3153
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.... Read more
Affected Products : atlas- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-3157
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to s... Read more
- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3161
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.... Read more
Affected Products : hadoop- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-3219
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.... Read more
Affected Products : true_image- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-3216
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password chang... Read more
Affected Products : ox350_firmware bm2022_firmware hes-309m_firmware hes-319m_firmware hes-319m2w_firmware hes-339m_firmware soho_wireless_router_firmware ox-330p_firmware max218m_firmware max218m1w_firmware +18 more products- Published: Jun. 20, 2017
- Modified: Apr. 20, 2025
-
6.0
MEDIUMCVE-2017-3246
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Patching). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows high privileg... Read more
Affected Products : application_object_library- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-3195
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.... Read more
Affected Products : edge- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-3191
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as... Read more
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-3212
The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : space_coast_credit_union- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-3251
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.16 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple p... Read more
Affected Products : mysql- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-3194
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.... Read more
Affected Products : pandora- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3215
The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions.... Read more
Affected Products : one-key- Published: Jun. 20, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-3264
Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Open UI). The supported version that is affected is 16.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise S... Read more
Affected Products : siebel_ui_framework- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3237
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the... Read more
Affected Products : automatic_service_request- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-3259
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multi... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-3192
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with... Read more
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-3213
The Think Mutual Bank Mobile Banking app 3.1.5 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : think_mutual_bank_mobile_banking_app- Published: May. 05, 2017
- Modified: Apr. 20, 2025