Latest CVE Feed
-
4.8
MEDIUMCVE-2016-8751
Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.... Read more
Affected Products : ranger- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-8746
Apache Ranger before 0.6.3 policy engine incorrectly matches paths in certain conditions when policy does not contain wildcards and has recursion flag set to true.... Read more
Affected Products : ranger- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-9502
In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overw... Read more
Affected Products : curl- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2810
An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnera... Read more
Affected Products : tablib- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0663
A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution i... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-0651
An information disclosure vulnerability in the kernel ION subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged process. Product... Read more
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-0650
An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged process.... Read more
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0649
An elevation of privilege vulnerability in the MediaTek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0648
An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of a local permanent device compro... Read more
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0647
An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Prod... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0646
An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate due to details specific to the vulnerability. Product: Android. Vers... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0645
An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it is a local bypass of user interaction requirements. Product: Androi... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0644
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. V... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0643
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. V... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0642
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product:... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0641
A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: ... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0640
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. V... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0639
An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it is a general bypass for operating system protections that iso... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0638
A remote code execution vulnerability in System UI component could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High because it is a remote arbitrary code... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0637
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025