Latest CVE Feed
-
5.5
MEDIUMCVE-2017-8535
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 17... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2016 exchange_server windows_defender security_essentials system_center_endpoint_protection +4 more products- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6862
NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allow authentication bypass and remote code execution via a buffer overflow that uses a parameter in the administration webapp. The NETGEAR... Read more
Affected Products : wnr2000v5_firmware wnr2000v4_firmware wnr2000v3_firmware wnr2000v5 wnr2000v4 wnr2000v3- Actively Exploited
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10375
Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c.... Read more
Affected Products : yodl- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2015-0269
Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end" users to view files outside their file mounts or the document root via unspecified vectors.... Read more
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7505
Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all operations granted by these permissions on all administrator user object out... Read more
Affected Products : foreman- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1325
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
Affected Products : inotes- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1292
IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks against the system. IBM X-Force ID: 125153.... Read more
Affected Products : maximo_application_suite maximo_asset_management maximo_asset_management_essentials- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1291
IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would al... Read more
Affected Products : maximo_application_suite maximo_asset_management maximo_asset_management_essentials- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9239
An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage will use the value of pValue() to cause a segmentation fau... Read more
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9037
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) S44, (2) S5, (3) S_action_fail, (4) S_ptn_update, (5) T113, (6) T114, (... Read more
Affected Products : serverprotect- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9036
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.... Read more
Affected Products : serverprotect- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-9035
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.... Read more
Affected Products : serverprotect- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9034
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failure to validate software updates.... Read more
Affected Products : serverprotect- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9033
Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authentication of users for requests to start an update from an arbitrary source via a crafted request to SProt... Read more
Affected Products : serverprotect- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9032
Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitrary web script or HTML via the (1) T1 or (2) tmLastConfigFileModifiedDate parameter to log_management.cgi.... Read more
Affected Products : serverprotect- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7439
NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages.... Read more
Affected Products : oncommand_unified_manager_core_package- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7236
SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : oncommand_unified_manager_core_package- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5868
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via "%0A" characters i... Read more
Affected Products : openvpn_access_server- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcellerator/exec/soap/vP.001sap0003.in_WCSX/com.sap.b1i.vplatform.runtime/INB_WS_CALL_SYNC_XPT/INB_WS_CALL_SYNC... Read more
Affected Products : business_one- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5007
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechani... Read more
- Published: May. 25, 2017
- Modified: Apr. 20, 2025