Latest CVE Feed
-
7.5
HIGHCVE-2016-7508
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.... Read more
Affected Products : glpi- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-7922
An Improper Privilege Management issue was discovered in Cambium Networks ePMP. The privileges for SNMP community strings are not properly restricted, which may allow an attacker to gain access to sensitive information and possibly allow for configuration... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-7918
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able to remotely trigger device configuration backups using specific MIBs. These backups lack proper access con... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6053
A Cross-Site Scripting issue was discovered in Trihedral VTScada Versions prior to 11.2.26. A cross-site scripting vulnerability may allow JavaScript code supplied by the attacker to execute within the user's browser.... Read more
Affected Products : vtscada- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6050
A SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which may allow for an unauthenticated attacker to remotely execute arbitrary code in the form of SQL queries.... Read more
Affected Products : integraxor- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6045
An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application to unauthenticated users. These files may contain sensitive configuration information.... Read more
Affected Products : vtscada- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6043
A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit the amount of resources that are utilized by an attacker, which can be used to consume more resources than... Read more
Affected Products : vtscada- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2813
An exploitable integer overflow vulnerability exists in the JPEG 2000 parser functionality of IrfanView 4.44. A specially crafted jpeg2000 image can cause an integer overflow leading to wrong memory allocation resulting in arbitrary code execution. Vulner... Read more
Affected Products : irfanview- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8731
Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials would allow remote access to any cameras found on the internet that do not have port 50021 blocked by an intermediate device.... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9781
A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.4.0x prior to 1.4.0p6, allowing an unauthenticated remote attacker to inject arbitrary HTML or JavaScript via the _username parameter when attempting authentication to webapi.py, whi... Read more
Affected Products : check_mk- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9774
Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication.... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2017-9773
Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver.... Read more
Affected Products : horde_image- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2017-1304
IBM has identified a vulnerability with IBM Spectrum Scale/GPFS utilized on the Elastic Storage Server (ESS)/GPFS Storage Server (GSS) during testing of an unsupported configuration, where users applications are running on an active ESS I/O server node an... Read more
Affected Products : elastic_storage_server- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1117
IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user to cause a denial of service to the MQXR channel when trace is enabled. IBM X-Force ID: 121155.... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9780
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-2831
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitr... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-2830
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitr... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
7.7
HIGHCVE-2017-2829
An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause the application to read a file from disk but ... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2828
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2827
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters... Read more
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025