Latest CVE Feed
-
8.8
HIGHCVE-2017-9840
Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application.... Read more
- Published: Jun. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9848
SQL injection vulnerability in C_InfoService.asmx in WebServices in Easysite 7.0 could allow remote attackers to execute arbitrary SQL commands via an XML document containing a crafted ArticleIDs element within a GetArticleHitsArray element.... Read more
Affected Products : easysite- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9847
The bdecode function in bdecode.cpp in libtorrent 1.1.3 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.... Read more
Affected Products : libtorrent- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9846
Winmail Server 6.1 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php move_folder_file call to move a .php file from the FTP folder into a web folder.... Read more
Affected Products : winmail_server- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-9836
Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album).... Read more
Affected Products : piwigo- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9833
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one ty... Read more
Affected Products : boa- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-9832
An integer overflow vulnerability in ptp-pack.c (ptp_unpack_OPL function) of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a p... Read more
Affected Products : libmtp- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-9831
An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserti... Read more
Affected Products : libmtp- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9829
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnera... Read more
- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9828
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is alread... Read more
- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9772
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variab... Read more
- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1349
IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM X-Force ID: 126525.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1348
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1347
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1302
IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID: 125456.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1193
IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1132
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1131
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially crafted HTTP commands. IBM X-Force ID: 121375.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-5893
IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 115336.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-3948
Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing session.... Read more
Affected Products : data_loss_prevention_endpoint- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025