Latest CVE Feed
-
5.5
MEDIUMCVE-2015-9100
The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.... Read more
Affected Products : lame- Published: Jun. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-9099
The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate.... Read more
Affected Products : lame- Published: Jun. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9868
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.... Read more
- Published: Jun. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9865
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in ImageO... Read more
- Published: Jun. 25, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9840
Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application.... Read more
- Published: Jun. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9848
SQL injection vulnerability in C_InfoService.asmx in WebServices in Easysite 7.0 could allow remote attackers to execute arbitrary SQL commands via an XML document containing a crafted ArticleIDs element within a GetArticleHitsArray element.... Read more
Affected Products : easysite- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9847
The bdecode function in bdecode.cpp in libtorrent 1.1.3 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.... Read more
Affected Products : libtorrent- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9846
Winmail Server 6.1 allows remote code execution by authenticated users who leverage directory traversal in a netdisk.php move_folder_file call to move a .php file from the FTP folder into a web folder.... Read more
Affected Products : winmail_server- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-9836
Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album).... Read more
Affected Products : piwigo- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9833
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. NOTE: multiple third parties report that this is a system-integrator issue (e.g., a vulnerability on one ty... Read more
Affected Products : boa- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-9832
An integer overflow vulnerability in ptp-pack.c (ptp_unpack_OPL function) of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserting a mobile device into a p... Read more
Affected Products : libmtp- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-9831
An integer overflow vulnerability in the ptp_unpack_EOS_CustomFuncEx function of the ptp-pack.c file of libmtp (version 1.1.12 and below) allows attackers to cause a denial of service (out-of-bounds memory access) or maybe remote code execution by inserti... Read more
Affected Products : libmtp- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9829
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnera... Read more
- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9828
'/cgi-bin/admin/testserver.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable to shell command injection, which allows remote attackers to execute any shell command as root via a crafted HTTP request. This vulnerability is alread... Read more
- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9772
Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_NATIVE_CPLUGINS, or CAML_BYTE_CPLUGINS environment variab... Read more
- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1349
IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM X-Force ID: 126525.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1348
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1347
IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1302
IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID: 125456.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1193
IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.... Read more
Affected Products : sterling_b2b_integrator- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025