Latest CVE Feed
-
6.1
MEDIUMCVE-2017-12798
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.... Read more
Affected Products : nexusphp- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12817
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.... Read more
Affected Products : internet_security- Published: Aug. 25, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12800
The EBML_FindNextElement function in ebmlmain.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.... Read more
- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12823
Kernel pool memory corruption in one of drivers in Kaspersky Embedded Systems Security version 1.2.0.300 leads to local privilege escalation.... Read more
Affected Products : embedded_systems_security- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12811
PHPJabbers Star Rating Script 4.0 has stored XSS via a rating item.... Read more
Affected Products : phpjabbers_star_rating_script- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12816
In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the product functionality by using Android IPC.... Read more
Affected Products : internet_security- Published: Aug. 25, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12803
The Node_ValidatePtr function in corec/corec/node/node.c in mkclean 0.8.9 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.... Read more
Affected Products : mkclean- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12941
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.... Read more
Affected Products : unrar- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2017-12822
Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors.... Read more
Affected Products : sentinel_ldk_rte_firmware- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12856
Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to index.php.... Read more
Affected Products : c.p.sub- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-12870
SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to n... Read more
Affected Products : simplesamlphp- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12838
Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors.... Read more
Affected Products : nexusphp- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12868
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character convers... Read more
- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12874
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.... Read more
- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12934
ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploitation of this issue can have an uns... Read more
Affected Products : php- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12860
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-screen - ensuring only those who can view it are streaming.In addition to the pa... Read more
Affected Products : easymp- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-12844
Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated domain administrators to inject arbitrary web script or HTML via a crafted user name.... Read more
Affected Products : mail_server- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-12867
The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.... Read more
Affected Products : simplesamlphp- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12882
Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin before 1.3.0 allows remote authenticated users to inject arbitrary JavaScript or HTML via the file upload functionality.... Read more
Affected Products : spring_batch_admin- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-12847
Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification before a root scr... Read more
Affected Products : nagios- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025