Latest CVE Feed
-
9.8
CRITICALCVE-2017-16613
An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieved from the Swauth middleware authentication mechanism to... Read more
- Published: Nov. 21, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16635
In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module. Remote attackers with low-privilege user accounts for backend access are able to inject malicious script codes into the `T... Read more
Affected Products : tinywebgallery- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
4.4
MEDIUMCVE-2017-16637
In Vectura Perfect Privacy VPN Manager v1.10.10 and v1.10.11, when resetting the network data via the software client, with a running VPN connection, a critical error occurs which leads to a "FrmAdvancedProtection" crash. Although the mechanism malfunctio... Read more
Affected Products : vpn_manager- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16659
The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to install a Trojan horse /usr/share/assp/assp.pl script.... Read more
Affected Products : anti-spam_smtp_proxy- Published: Nov. 08, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-16650
The qmi_wwan_bind function in drivers/net/usb/qmi_wwan.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (divide-by-zero error and system crash) or possibly have unspecified other impact via a crafted USB device.... Read more
Affected Products : linux_kernel- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16664
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the webserver user via ... Read more
- Published: Nov. 21, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16663
In sam2p 0.49.4, there are integer overflows (with resultant heap-based buffer overflows) in input-bmp.ci in the function ReadImage, because "width * height" multiplications occur unsafely.... Read more
Affected Products : sam2p- Published: Nov. 08, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16683
Denial of Service (DOS) in SAP Business Objects Platform, Enterprise 4.10 and 4.20, that could allow an attacker to prevent legitimate users from accessing a service.... Read more
Affected Products : businessobjects- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16665
RemObjects Remoting SDK 9 1.0.0.0 for Delphi is vulnerable to a reflected Cross Site Scripting (XSS) attack via the service parameter to the /soap URI, triggering an invalid attempt to generate WSDL.... Read more
Affected Products : remoting_sdk_9- Published: Nov. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16669
coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick... Read more
- Published: Nov. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16783
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.... Read more
Affected Products : cms_made_simple- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16678
Server Side Request Forgery (SSRF) vulnerability in SAP NetWeaver Knowledge Management Configuration Service, EPBC and EPBC2 from 7.00 to 7.02; KMC-BC 7.30, 7.31, 7.40 and 7.50, that allows an attacker to manipulate the vulnerable application to send craf... Read more
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-16687
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error ... Read more
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16721
A Cross-site Scripting issue was discovered in Geovap Reliance SCADA Version 4.7.3 Update 2 and prior. This vulnerability could allow an unauthenticated attacker to inject arbitrary code.... Read more
Affected Products : reliance-scada- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16766
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.... Read more
- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-16725
A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability has been identified, which may allow an attacker to execute code remotely ... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-16733
A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has been identified, which an attacker can leverage to disclose sensitive information from the database.... Read more
Affected Products : integraxor- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-16754
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.... Read more
Affected Products : bolt- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16785
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.... Read more
Affected Products : cacti- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUM- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025