Latest CVE Feed
-
8.8
HIGHCVE-2017-16542
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.... Read more
- Published: Nov. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16541
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails ... Read more
- Published: Nov. 04, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16575
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16543
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.... Read more
- Published: Nov. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16581
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-16638
The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" group to gain root privileges by creating a hard link in a directory on which "chown" is called recursively by the OpenRC service script.... Read more
Affected Products : vde- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16589
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-16661
Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/pa... Read more
Affected Products : cacti- Published: Nov. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-16560
SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefinitely in certain situations, such as if the file is being edited when the user exits the application or if the application crashes.... Read more
Affected Products : secureaccess- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16583
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16562
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the ... Read more
Affected Products : userpro- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16642
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the interpr... Read more
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16565
Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.... Read more
- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16577
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16584
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16579
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-16649
The usbnet_generic_cdc_bind function in drivers/net/usb/cdc_ether.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (divide-by-zero error and system crash) or possibly have unspecified other impact via a crafted USB dev... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16561
/view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL injection in the 'friend_index' parameter of a GET request.... Read more
Affected Products : ingenious_school_management_system- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16585
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16618
An exploitable vulnerability exists in the YAML loading functionality of util.py in OwlMixin before 2.0.0a12. A "Load YAML" string or file (aka load_yaml or load_yamlf) can execute arbitrary Python commands resulting in command execution because load is u... Read more
Affected Products : owlmixin- Published: Nov. 08, 2017
- Modified: Apr. 20, 2025