Latest CVE Feed
-
7.2
HIGHCVE-2017-12312
An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the ins... Read more
Affected Products : advanced_malware_protection_for_endpoints- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12281
A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an unauthenticated, adjacent attacker to bypass... Read more
Affected Products : aironet_2800_firmware aironet_3800_firmware aironet_1800_firmware aironet_1830e aironet_1830i aironet_1850e aironet_1850i aironet_2800e aironet_2800i aironet_3800e +2 more products- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2017-12297
A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to arbitrary hosts, aka a "URL Redirection Vulnerability." The vulnerability is due to insufficient access control for HTTP traffic directe... Read more
Affected Products : webex_meeting_center- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12283
A vulnerability in the handling of 802.11w Protected Management Frames (PAF) by Cisco Aironet 3800 Series Access Points could allow an unauthenticated, adjacent attacker to terminate a valid user connection to an affected device, aka Denial of Service. Th... Read more
- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-12302
A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The vulnerability is due to... Read more
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-12286
A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to ... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-12477
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xinetd, has an issue in which its authentication can be bypassed. A remote attacker could use this issue to execute arbitrary commands wit... Read more
Affected Products : unitrends_backup- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
4.4
MEDIUMCVE-2017-12289
A vulnerability in conditional, verbose debug logging for the IPsec feature of Cisco IOS XE Software could allow an authenticated, local attacker to display sensitive IPsec information in the system log file. The vulnerability is due to incorrect implemen... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-12365
A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information. The vulnerability is due to a design flaw in the product. An attacker could execute a query on an Event Center site to view sch... Read more
Affected Products : webex_meeting_center- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-12369
A "Cisco WebEx Network Recording Player Out-of-Bounds Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user with a... Read more
Affected Products : webex_meetings- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12598
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 8-opencv-invali... Read more
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12299
A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall Services that could allow an unauthenticated, remote attacker to send traffic to the local IP address of the device, by... Read more
Affected Products : firepower_extensible_operating_system- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.7
MEDIUMCVE-2017-12333
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software images. An authe... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-12345
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client ... Read more
Affected Products : data_center_network_manager- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12356
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of... Read more
Affected Products : jabber- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12344
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client ... Read more
Affected Products : data_center_network_manager- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12357
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected ... Read more
Affected Products : unified_communications_manager- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-12367
A "Cisco WebEx Network Recording Player Denial of Service Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) and WebEx Recording Format (WRF) files. A remote attacker could exploit this by providing a user wi... Read more
Affected Products : webex_meetings_server- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12314
A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to the device availability, confidentiality, and integrity, aka Insecure Li... Read more
Affected Products : findit_network_discovery_utility- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12355
A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause one of the LPTS processes on an affected system to restart unexpectedly,... Read more
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025