Latest CVE Feed
-
5.5
MEDIUMCVE-2017-3747
Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected) that could allow an attacker with local privileges on a system to alter registry keys.... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5529
JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versio... Read more
Affected Products : jasperreports_server jasperreports_library_community_edition jasperreports_library_for_activematrix_bpm jasperreports_professional jasperreports_server_community_edition jasperreports_server_for_activematrix_bpm jaspersoft_for_aws_with_multi-tenancy jaspersoft_reporting_and_analytics_for_aws jaspersoft_studio_for_activematrix_bpm- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5528
Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-8613
Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability."... Read more
Affected Products : azure_active_directory_connect- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-8579
The DirectX component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "DirectX Elevation of Privilege Vulnerability."... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-8576
The graphics component in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to run arbitrary code in kernel mode via a specially crafted application, aka "Microsoft Graphics Component Elevation of Privil... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8575
The kernel in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a specially crafted application, aka "Microsoft Graphics Component Information Disclosure Vulnerability."... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8558
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold,... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-8554
The kernel in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an authenticated attacker to obtain memory content... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1310
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-... Read more
Affected Products : informix_dynamic_server- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10673
admin/profile.php in GetSimple CMS 3.x has XSS in a name field.... Read more
Affected Products : getsimple_cms- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10672
Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10671
Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename.... Read more
Affected Products : sthttpd- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10667
In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS.... Read more
Affected Products : zen_cart- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10042
Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and inform... Read more
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1106
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : curam_social_program_management- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7686
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server ... Read more
Affected Products : ignite- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5241
Biscom Secure File Transfer versions 5.0.0.0 trough 5.1.1024 are vulnerable to post-authentication persistent cross-site scripting (XSS) in the "Name" and "Description" fields of a Workspace, as well as the "Description" field of a File Details pane of a ... Read more
Affected Products : secure_file_transfer- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9998
The _dwarf_decode_s_leb128_chk function in dwarf_leb.c in libdwarf through 2017-06-28 allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.... Read more
Affected Products : libdwarf- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9996
The cdxl_decode_frame function in libavcodec/cdxl.c in FFmpeg 2.8.x before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not exclude the CHUNKY format, which allows remote attackers to cause a denial of se... Read more
Affected Products : ffmpeg- Published: Jun. 28, 2017
- Modified: Apr. 20, 2025