Latest CVE Feed
-
7.5
HIGHCVE-2016-10367
In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP G... Read more
Affected Products : opsview- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-9058
Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.... Read more
Affected Products : proxmox_mail_gateway- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-9057
Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multiple parameters, related to /users/index.htm, /quarantine/spam/manage.htm, /qu... Read more
Affected Products : proxmox_mail_gateway- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8455
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.... Read more
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8454
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.... Read more
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8453
Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 have an out-of-bounds read that allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted font in a PDF document.... Read more
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7432
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.... Read more
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7431
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.... Read more
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7430
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.... Read more
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-7428
NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.... Read more
Affected Products : imanager- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0331
An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device co... Read more
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9004
kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.... Read more
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2014-9940
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.... Read more
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-8421
The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional va... Read more
Affected Products : binutils- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7476
Gnulib before 2017-04-26 has a heap-based buffer overflow with the TZ environment variable. The error is in the save_abbr function in time_rz.c.... Read more
Affected Products : gnulib- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7216
The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecified request parameters.... Read more
Affected Products : pan-os- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8419
LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overflow or heap-based buffer overflow) or possibly have unspecified other impact... Read more
Affected Products : lame- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-8418
RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.... Read more
Affected Products : rubocop- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8112
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.... Read more
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8086
Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value variable.... Read more
- Published: May. 02, 2017
- Modified: Apr. 20, 2025