Latest CVE Feed
-
7.6
HIGHCVE-2017-11843
ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 a... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-2702
Phone Finder in versions earlier before MHA-AL00C00B170 can be bypass. An attacker can bypass the Phone Finder by special steps and obtain the owner of the phone.... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11873
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "S... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2689
Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or change configuration settings.... Read more
Affected Products : ruggedcom_rox_i- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2017-15707
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.... Read more
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11894
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and and Internet Explorer adn Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows ... Read more
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11912
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Serv... Read more
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11936
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability".... Read more
Affected Products : sharepoint_enterprise_server- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2693
ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier versions,ALE-L21C432B214 and earlier versions,ALE-L21C464B150 and earlier versions,ALE-L21C636B200 and earlier versio... Read more
Affected Products : mate_7_firmware p8_lite_firmware mate_s_firmware p8_firmware honor_6_firmware honor_7_firmware shotx_firmware g8_firmware p8 mate_7 +6 more products- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2017-2710
BTV-W09C229B002CUSTC229D005,BTV-W09C233B029, earlier than BTV-W09C100B006CUSTC100D002 versions, earlier than BTV-W09C128B003CUSTC128D002 versions, earlier than BTV-W09C199B002CUSTC199D002 versions, earlier than BTV-W09C209B005CUSTC209D001 versions, earlie... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-12132
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.... Read more
Affected Products : glibc- Published: Aug. 01, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-12153
A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be issued... Read more
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2692
The Keyguard application in ALE-L02C635B140 and earlier versions,ALE-L02C636B140 and earlier versions,ALE-L21C10B150 and earlier versions,ALE-L21C185B200 and earlier versions,ALE-L21C432B214 and earlier versions,ALE-L21C464B150 and earlier versions,ALE-L2... Read more
Affected Products : mate_7_firmware p8_lite_firmware mate_s_firmware p8_firmware honor_6_firmware honor_7_firmware shotx_firmware g8_firmware p8 mate_7 +6 more products- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-2706
Mate 9 smartphones with software MHA-AL00AC00B125 have a directory traversal vulnerability in Push module. Since the system does not verify the file name during decompression, system directories are traversed. It could be exploited to cause the attacker t... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2017-2727
Huawei P9 smart phones with software versions earlier before EVA-AL00C00B365, versions earlier before EVA-AL10C00B365,Versions earlier before EVA-CL00C92B365, versions earlier before EVA-DL00C17B365, versions earlier before EVA-TL00C01B365 have a privileg... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-2695
TIT-AL00C583B211 has a directory traversal vulnerability which allows an attacker to obtain the files in email application.... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2715
The Files APP 7.1.1.309 and earlier versions in some Huawei mobile phones has a brute-force password cracking vulnerability due to the improper design of the Safe key database. An unauthorized attacker could access sensitive database information and may c... Read more
Affected Products : files- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1222
IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 123862.... Read more
Affected Products : bigfix_platform- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2248
Untrusted search path vulnerability in Installer of Lhaz+ version 3.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : lhaz\+- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2271
Untrusted search path vulnerability in Self-extracting encrypted files created by AttacheCase ver.2.8.3.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : attachecase- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025