Latest CVE Feed
-
4.3
MEDIUMCVE-2017-1326
IBM Sterling File Gateway does not properly restrict user requests based on permission level. This allows for users to update data related to other users, by manipulating the parameters passed in the POST request. IBM X-Force ID: 126060.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9983
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-9982
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to improper access control. IBM X-Force ID: 120274.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9747
IBM RELM 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessi... Read more
Affected Products : rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9424
IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.... Read more
Affected Products : breeze.server.net- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9815
In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function _TIFFmalloc in tif_unix.c) via a crafted file.... Read more
- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0176
A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows ... Read more
- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3631
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solari... Read more
- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3630
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where ... Read more
- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3629
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where ... Read more
- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2012-6706
A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. An integer overflow can be caused in DataSize+CurChannel... Read more
- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9807
An issue was discovered in the OpenWebif plugin through 1.2.4 for E2 open devices. The saveConfig function of "plugin/controllers/models/config.py" performs an eval() call on the contents of the "key" HTTP GET parameter. This allows an unauthenticated rem... Read more
Affected Products : openwebif- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9782
JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c.... Read more
Affected Products : jasper- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-4990
In EMC Avamar Server Software 7.4.1-58, 7.4.0-242, 7.3.1-125, 7.3.0-233, 7.3.0-226, an unauthorized attacker may leverage the file upload feature of the system maintenance page to load a maliciously crafted file to any directory which could allow the atta... Read more
Affected Products : avamar_server- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-4989
In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypass the authentication process to gain access to the system maintenance page. This may be exploited by an a... Read more
Affected Products : avamar_server- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-4988
EMC Isilon OneFS 8.0.1.0, 8.0.0 - 8.0.0.3, 7.2.0 - 7.2.1.4, 7.1.x is affected by a privilege escalation vulnerability that could potentially be exploited by attackers to compromise the affected system.... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-3219
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.... Read more
Affected Products : true_image- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-3218
Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.... Read more
Affected Products : magician- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-7508
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.... Read more
Affected Products : glpi- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-7922
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025