Latest CVE Feed
-
6.1
MEDIUMCVE-2017-15291
Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description field.... Read more
- Published: Oct. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15286
SQLite 3.20.1 has a NULL pointer dereference in tableColumnList in shell.c because it fails to consider certain cases where `sqlite3_step(pStmt)==SQLITE_ROW` is false and a data structure is never initialized.... Read more
Affected Products : sqlite- Published: Oct. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-15316
The GPU driver of Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate 9 Pro Huawei smart phones with software before LON-AL00B 8.0.0.334(C00) has a memory double free vulnerability. An attacker tricks a user into installing a... Read more
- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-15295
Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.... Read more
Affected Products : point_of_sale_xpress_server- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15311
The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00), and before LON-AL00B 8.0.0.334(C00) have a stack over... Read more
Affected Products : mate_10_pro_firmware mate_10_firmware mate_9_pro_firmware mate_9_firmware mate_9 mate_9_pro mate_10 mate_10_pro- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15297
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.... Read more
Affected Products : host_agent- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15308
Huawei iReader app before 8.0.2.301 has an input validation vulnerability due to insufficient validation on the URL used for loading network data. An attacker can control app access and load malicious websites created by the attacker, and the code in webp... Read more
Affected Products : ireader- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15281
ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to "Conditional jump or move depends on uninitialised value(... Read more
- Published: Oct. 12, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15321
Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) has an information leak vulnerability due to the use of a low version transmission protocol by default. An attacker could intercept packets transferred by a target device. Successful exploit could cau... Read more
- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15303
In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because any program running on the local machine (while CPU-Z is running) can issue an ioctl 0x9C402430 call to the kernel-mode driver (e.g., ... Read more
Affected Products : cpu-z- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15310
Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vulnerability to delete specific files from the SD card.... Read more
Affected Products : ireader- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-15300
The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort of request is made (such as "GET / HTTP/1.1"), which allows for a Denial of Service attack preventing a user from viewing their mining ... Read more
Affected Products : cuda_zcash_miner- Published: Oct. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15305
XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.... Read more
Affected Products : nexusphp- Published: Oct. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15375
Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query` and `id` parameters of the `wpjb-email`, `wpjb-job`, `wpjb-application`, ... Read more
Affected Products : wpjobboard- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-15309
Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.... Read more
Affected Products : ireader- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15364
The foreach function in ext/ccsv.c in Ccsv 1.1.0 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact via a crafted file. NOTE: This has been disputed and it is argued that this... Read more
Affected Products : ccsv- Published: Oct. 15, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15328
Huawei HG8245H version earlier than V300R018C00SPC110 has an authentication bypass vulnerability. An attacker can access a specific URL of the affect product. Due to improper verification of the privilege, successful exploitation may cause information lea... Read more
- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15359
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters. An attacker must... Read more
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15324
Huawei S5700 and S6700 with software of V200R005C00 have a DoS vulnerability due to insufficient validation of the Network Quality Analysis (NQA) packets. A remote attacker could exploit this vulnerability by sending malformed NQA packets to the target de... Read more
- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-15376
The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23.... Read more
Affected Products : mobaxterm- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025