Latest CVE Feed
-
4.6
MEDIUMCVE-2017-8900
LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users by establishing a guest session.... Read more
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8360
Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keystrokes) to any process. In mictray64.exe (mic tray icon) 1.0.0.46, a LowLevelKeyboardProc Windows hook is used to capture keystrokes. Th... Read more
Affected Products : windows_10 windows_7 mictray64 elitebook_725_g3 elitebook_745_g3 elitebook_755_g3 zbook_15_g3 zbook_15u_g3 zbook_17_g3 elitebook_820_g3 +19 more products- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8906
An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x265 through 2.4, as used by the x265_encoder_encode dependency in libbpg and other products. A small picture can cause an integer under... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8905
Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-215.... Read more
Affected Products : xen- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8904
Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.... Read more
Affected Products : xen- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8903
Xen through 4.8.x on 64-bit platforms mishandles page tables after an IRET hypercall, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-213.... Read more
Affected Products : xen- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7472
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.... Read more
Affected Products : linux_kernel- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8851
An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both products use the same OTA verification keys, and the fact that both products share the same 'ro.build.product' sy... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-8850
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both ROMs use the same OTA verification keys, attackers can install HydrogenOS over OxygenOS and vice versa, even... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5948
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenient 'updater-script' in OTAs that does not check that the current version is lower than or equal to the give... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10370
An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-8899
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclosure issues in the attachments feature found in User CP. This can be triggered by any Invision Power Board user and can be used to gain ... Read more
Affected Products : invision_power_board- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8898
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privilege escalation from an Invision Power Board moderator to an admin. An attack uses the announce_content parameter in an index.php?/modcp/... Read more
Affected Products : invision_power_board- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8897
Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter v1.1.18: admin/convertutf8/index.php?controller= is the attack vector. This UTF8 Converter vulnerability can easily be used to make a m... Read more
Affected Products : invision_power_board- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-7476
The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, 11.5.0 before 11.5.3 HF2, and 11.3.0 before 11.4.1 HF10 may suffer from a memory leak while handling certa... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager big-ip_websafe big-ip_protocol_security_module- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-9100
Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.13, ASG 6.7 prior to 6.7.3.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6 prior to 6.6.5.13, and ProxySG 6.7 prior to 6.7.3.1 are susceptible to an information disclosure vulnerability. An attacker ... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9099
Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 prior to 6.7.2.1, ProxySG 6.5 prior to 6.5.10.6, ProxySG 6.6, and ProxySG 6.7 prior to 6.7.2.1 are susceptible to an open redirection vulnerability. A remote attacker can use a crafted management console... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2016-9097
The Symantec Advanced Secure Gateway (ASG) 6.6 prior to 6.6.5.8, ProxySG 6.5 prior 6.5.10.6, ProxySG 6.6 prior to 6.6.5.8, and ProxySG 6.7 prior to 6.7.1.2 management consoles do not, under certain circumstances, correctly authorize administrator users. A... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-9092
The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote attacker can use phishing or other social engineering techni... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-2126
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos tic... Read more
Affected Products : samba- Published: May. 11, 2017
- Modified: Apr. 20, 2025