Latest CVE Feed
-
6.5
MEDIUMCVE-2017-3118
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has a security bypass vulnerability related to execution of malicious attachments.... Read more
- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3127
A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.... Read more
Affected Products : fortios- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-3167
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.... Read more
- Published: Jun. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3132
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.... Read more
Affected Products : fortios- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-3131
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.... Read more
Affected Products : fortios- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3166
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable lo... Read more
Affected Products : hadoop- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3150
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.... Read more
Affected Products : atlas- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-3134
An escalation of privilege vulnerability in Fortinet FortiWLC-SD versions 8.2.4 and below allows attacker to gain root access via the CLI command 'copy running-config'.... Read more
Affected Products : fortiwlc-sd- Published: May. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3153
Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.... Read more
Affected Products : atlas- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-3157
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections to s... Read more
- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3161
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.... Read more
Affected Products : hadoop- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-3219
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.... Read more
Affected Products : true_image- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-3216
WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password chang... Read more
Affected Products : ox350_firmware bm2022_firmware hes-309m_firmware hes-319m_firmware hes-319m2w_firmware hes-339m_firmware soho_wireless_router_firmware ox-330p_firmware max218m_firmware max218m1w_firmware +18 more products- Published: Jun. 20, 2017
- Modified: Apr. 20, 2025
-
6.0
MEDIUMCVE-2017-3246
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Patching). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows high privileg... Read more
Affected Products : application_object_library- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-3195
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.... Read more
Affected Products : edge- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-3191
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as... Read more
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-3212
The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : space_coast_credit_union- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-3251
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.16 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple p... Read more
Affected Products : mysql- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-3194
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.... Read more
Affected Products : pandora- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3215
The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions.... Read more
Affected Products : one-key- Published: Jun. 20, 2017
- Modified: Apr. 20, 2025