Latest CVE Feed
-
7.1
HIGHCVE-2017-2681
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.... Read more
Affected Products : simatic_s7-1500_software_controller_firmware scalance_m-800_firmware scalance_s615_firmware scalance_x408_firmware scalance_x300_firmware scalance_x414_firmware simatic_et_200sp_firmware simatic_s7-1500_firmware scalance_x200_firmware simatic_cp_1243-1_firmware +165 more products- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8798
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5461
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact... Read more
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-2680
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.... Read more
Affected Products : simatic_s7-1500_software_controller_firmware scalance_m-800_firmware scalance_s615_firmware scalance_x408_firmware scalance_x300_firmware scalance_x414_firmware simatic_et_200sp_firmware simatic_s7-1500_firmware scalance_x200_firmware simatic_cp_1243-1_firmware +192 more products- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8895
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attack... Read more
Affected Products : backup_exec- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8892
Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3 allows remote attackers to inject arbitrary web script or HTML persistently via the name of an uploaded image.... Read more
Affected Products : tempo_box- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8852
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted remote source. The problem is that the length of data written is an arbitrary number found within the file.... Read more
Affected Products : sapcar- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8891
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.... Read more
Affected Products : lepton- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8890
The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3894
A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator by... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-8879
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.... Read more
Affected Products : dolibarr_erp\/crm- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7888
Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.... Read more
Affected Products : dolibarr_erp\/crm- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7887
Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7886
Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7698
A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via a malformed PDF document, possibly a consequence of an error in Gfx.cc in Xpdf 3.02.... Read more
Affected Products : swftools- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
3.8
LOWCVE-2017-4896
Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-4895
Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-1137
IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549.... Read more
Affected Products : websphere_application_server- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-1103
IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all availabl... Read more
Affected Products : rational_collaborative_lifecycle_management rational_quality_manager rational_team_concert- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9250
In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +4 more products- Published: May. 10, 2017
- Modified: Apr. 20, 2025