Latest CVE Feed
-
5.4
MEDIUMCVE-2017-1287
IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL display... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1249
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1245
IBM Rational Software Architect Design Manager 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials ... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-8975
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6118
IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-9554
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9553
A design flaw in SYNO.API.Encryption in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to bypass the encryption protection mechanism via the crafted version parameter.... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8036
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release version 1.33.0 (only). The original fix for CVE-2017-8033 included in CAPI-release 1.33.0 introduces a regression that allows a space developer to execute arbitra... Read more
Affected Products : capi-release- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-7703
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with k... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11327
An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP resources such as admin/content.php and admin/content.php?method=ftp_upload.... Read more
Affected Products : tilde_cms- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11326
An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipulation.... Read more
Affected Products : tilde_cms- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11325
An issue was discovered in Tilde CMS 1.0.1. Arbitrary files can be read via a file=../ attack on actionphp/download.File.php.... Read more
Affected Products : tilde_cms- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11324
An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be triggered via a POST request to /actionphp/action.input.php wi... Read more
Affected Products : tilde_cms- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10711
In SimpleRisk 20170614-001, a CSRF attack on reset.php (aka the Send Password Reset Email form) can insert XSS sequences via the user parameter.... Read more
Affected Products : simplerisk- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11608
There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.... Read more
Affected Products : libsass- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11422
Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.... Read more
Affected Products : statamic- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11605
There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack.... Read more
Affected Products : libsass- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-11600
net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy_id is XFRM_POLICY_MAX or less, which allows local users to cause a denial of service (out-of-bounds acces... Read more
Affected Products : linux_kernel- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11594
Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment.... Read more
Affected Products : loomio- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11593
Cross-site scripting (XSS) vulnerability in the Markdown Preview Plus extension before 0.5.7 for Chrome allows remote attackers to inject arbitrary web script or HTML into some web applications via the upload and display of crafted text, markdown, or rst ... Read more
Affected Products : markdown_preview_plus- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025