Latest CVE Feed
-
7.5
HIGHCVE-2016-2225
The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet.... Read more
Affected Products : uclibc-ng- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-2103
The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : lala_call- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2123
Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via language.php.... Read more
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-2318
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath func... Read more
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-2120
SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : wbce_cms- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2229
Untrusted search path vulnerability in Douroshisetu Kihon Data Sakusei System Ver1.0.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : kihon_data_sakusei_system- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-2365
A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a null pointer dereference. A malicious server or an attacker who intercepts the network t... Read more
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2125
Privilege escalation vulnerability in CentreCOM AR260S V2 remote authenticated attackers to gain privileges via the guest account.... Read more
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2172
Cross-site scripting vulnerability in Cybozu KUNAI for Android 3.0.0 to 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : kunai- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2016-2516
NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.... Read more
Affected Products : ntp- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-2517
NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of tr... Read more
Affected Products : ntp- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-2132
Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to delete arbitrary files in a specific directory via unspecified vectors.... Read more
- Published: Oct. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2167
Untrusted search path vulnerability in Installer for PrimeDrive Desktop Application version 1.4.4 and earlier allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory.... Read more
Affected Products : primedrive_desktop_application- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2137
ProSAFE Plus Configuration Utility prior to 2.3.29 allows remote attackers to bypass access restriction and change configurations of the switch via SOAP requests.... Read more
Affected Products : prosafe_plus_configuration_utility- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-2152
WNC01WH firmware 1.0.0.9 and earlier allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-2142
Buffer overflow in WN-G300R3 firmware Ver.1.03 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2164
Cross-site scripting vulnerability in SOY CMS with installer 1.8.12 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : soy_cms- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2138
Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of a... Read more
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2191
Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2140
Tablacus Explorer 17.3.30 and earlier allows arbitrary scripts to be executed in the context of the application due to specially crafted directory.... Read more
Affected Products : tablacus_explorer- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025