Latest CVE Feed
-
8.1
HIGHCVE-2015-0839
The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by leveraging use of a short GPG key id from a keyserver to verify print plugin downloads.... Read more
Affected Products : linux_imaging_and_printing- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1560
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : rational_doors_next_generation- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1593
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : rational_doors_next_generation- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1558
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the... Read more
Affected Products : maximo_application_suite maximo_asset_management maximo_asset_management_essentials- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1583
IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote attacker to obtain sensitive information caused by improper error handling by MyFaces in JSF.... Read more
Affected Products : liberty- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1596
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132550.... Read more
Affected Products : security_guardium- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-1332
The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted website.... Read more
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1591
IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo... Read more
Affected Products : datapower_gateway- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2015-1838
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-1854
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.... Read more
- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-1694
IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker using man in the middle techniques. IBM X-Force ID: 134165.... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1710
A vulnerability in the Service Assistant GUI in IBM Storwize V7000 (2076) 8.1 could allow a remote attacker to perform a privilege escalation. IBM X-Force ID: 134531.... Read more
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2015-4100
Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."... Read more
Affected Products : puppet_enterprise- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1746
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 135519.... Read more
Affected Products : jazz_for_service_management- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1751
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti... Read more
Affected Products : robotic_process_automation_with_automation_anywhere- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1757
IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 135858.... Read more
Affected Products : security_guardium- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-5177
Double free vulnerability in the SLPDKnownDAAdd function in slpd/slpd_knownda.c in OpenSLP 1.2.1 allows remote attackers to cause a denial of service (crash) via a crafted package.... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-5594
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a crafted string.... Read more
Affected Products : zenphoto- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-7501
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Por... Read more
- Published: Nov. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-7504
Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (instance crash) or possibly execute arbitrary code via a series of packets in loopback mode.... Read more
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025