Latest CVE Feed
-
6.6
MEDIUMCVE-2017-8034
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi... Read more
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8011
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with defa... Read more
Affected Products : emc_m\&r emc_storage_monitoring_and_reporting emc_vipr_srm emc_vnx_monitoring_and_reporting- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8006
In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that user's PIN. The malicious user cou... Read more
Affected Products : rsa_authentication_manager- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-8005
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Ident... Read more
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-8004
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identi... Read more
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-8000
In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA Security Console Administrator could craft a token profile and store the profile name in the RSA Authentication Manager database. The profile name could include a crafted script (with ... Read more
Affected Products : rsa_authentication_manager- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9951
The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-... Read more
Affected Products : memcached- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9814
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.... Read more
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7688
Apache OpenMeetings 1.0.0 updates user password in insecure manner.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-7685
Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7684
Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files to the server.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7683
Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2017-7682
Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted areas.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7681
Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7680
Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from untrusted domains.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7673
Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget password dialogs and auth forms missing brute force protection.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7666
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-7664
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7663
Both global and Room chat are vulnerable to XSS attack in Apache OpenMeetings 3.2.0.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3103
Adobe Connect versions 9.6.1 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to a stored cross-site scripting attack.... Read more
Affected Products : connect- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025