Latest CVE Feed
-
7.1
HIGHCVE-2017-6024
A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 controllers V29.011; CompactLogix 5380 controllers V28.011; and CompactLogix 5380 controllers V29.011. This vu... Read more
Affected Products : compactlogix_5380_firmware controllogix_5580_firmware compactlogix_5380 controllogix_5580- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-6877
Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host header and a cached page. NOTE: the vendor reports "our internal analysis of this issue concluded that this w... Read more
Affected Products : xenmobile_server- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8801
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.... Read more
Affected Products : officescan- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1156
IBM WebSphere Portal 8.5 and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL di... Read more
Affected Products : websphere_portal- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2016-9692
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-s... Read more
Affected Products : websphere_cast_iron_solution- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-9691
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive informa... Read more
Affected Products : websphere_cast_iron_solution- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8916
IBM Tivoli Storage Manager 5.5, 6.1-6.4, and 7.1 stores password information in a log file that could be read by a local user when a set password command is issued. IBM X-Force ID: 118472.... Read more
Affected Products : tivoli_storage_manager- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-0255
IBM Marketing Platform 9.1 and 10.0 is vulnerable to stored cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed i... Read more
Affected Products : marketing_platform- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8799
Untrusted input execution via igetwild in all iRODS versions before 4.1.11 and 4.2.1 allows other iRODS users (potentially anonymous) to execute remote shell commands via iRODS virtual pathnames. To exploit this vulnerability, a virtual iRODS pathname tha... Read more
Affected Products : irods- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8796
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php allows SQL injection with the app_id parameter.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8795
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-8794
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8793
An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin ... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8792
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/user_add.html with the param parameter.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8791
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos/courier/login.html auth_params CRLF attack vector.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8790
An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8789
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8788
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF vulnerability in settings_global_text_edit.php allowing ?display=x%0Dnewline attacks.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8760
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypasse... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8304
An issue was discovered on Accellion FTA devices before FTA_9_12_180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.... Read more
Affected Products : file_transfer_appliance- Published: May. 05, 2017
- Modified: Apr. 20, 2025