Latest CVE Feed
-
6.5
MEDIUMCVE-2017-0170
Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability due t... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_server_2008 windows_server_2012 windows_server_2016- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11171
Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establish ICE connections to gnome-session with invalid authentication data (an inva... Read more
Affected Products : gnome-session- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11170
The ReadTGAImage function in coders\tga.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via invalid colors data in the header of a TGA or VST file.... Read more
Affected Products : imagemagick- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7730
iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding.... Read more
- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7729
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.... Read more
- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7728
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography.... Read more
- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7726
iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.... Read more
- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-10600
ubuntu-image 1.0 before 2017-07-07, when invoked as non-root, creates files in the resulting image with the uid of the invoking user. When the resulting image is booted, a local attacker with the same uid as the image creator has unintended access to clou... Read more
Affected Products : ubuntu-image- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11164
In PCRE 8.41, the OP_KETRMAX feature in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion) when processing a crafted regular expression.... Read more
Affected Products : pcre- Published: Jul. 11, 2017
- Modified: Apr. 20, 2025
-
6.6
MEDIUMCVE-2017-8032
In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-r... Read more
Affected Products : cloud_foundry_uaa user_account_and_authentication cloud_foundry_uaa_bosh cloud_foundry_cf- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6735
A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated, local attacker to execute arbitrary code on a targeted system. More Information: CSCvc91092. Known Affected Releases: 6.2.0 6.2.1.... Read more
Affected Products : firesight_system_software- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6734
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected device, ... Read more
Affected Products : identity_services_engine- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6733
A vulnerability in the web-based application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affec... Read more
Affected Products : identity_services_engine- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6732
A vulnerability in the installation procedure for Cisco Prime Network Software could allow an authenticated, local attacker to elevate their privileges to root privileges. More Information: CSCvd47343. Known Affected Releases: 4.2(2.1)PP1 4.2(3.0)PP6 4.3(... Read more
Affected Products : prime_network- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6731
A vulnerability in Multicast Source Discovery Protocol (MSDP) ingress packet processing for Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the MSDP session to be unexpectedly reset, causing a short denial of service (DoS) c... Read more
- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6730
A vulnerability in the web-based GUI of Cisco Wide Area Application Services (WAAS) Central Manager could allow an unauthenticated, remote attacker to retrieve completed reports from an affected system, aka Information Disclosure. This vulnerability affec... Read more
Affected Products : wide_area_application_services- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6729
A vulnerability in the Border Gateway Protocol (BGP) processing functionality of the Cisco StarOS operating system for Cisco ASR 5000 Series Routers and Cisco Virtualized Packet Core (VPC) Software could allow an unauthenticated, remote attacker to cause ... Read more
- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-6728
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary code at the root privilege level on an affected system, because of Incorrect Permissions. More Information: CSCvb99389. Known Affected Re... Read more
- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6727
A vulnerability in the Server Message Block (SMB) protocol of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device due to a process restarting unexpe... Read more
Affected Products : wide_area_application_services- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6726
A vulnerability in the CLI of the Cisco Prime Network Gateway could allow an authenticated, local attacker to retrieve system process information, which could lead to the disclosure of confidential information. More Information: CSCvd59341. Known Affected... Read more
Affected Products : prime_network- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025