Latest CVE Feed
-
7.1
HIGHCVE-2017-2680
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.... Read more
Affected Products : simatic_s7-1500_software_controller_firmware scalance_m-800_firmware scalance_s615_firmware scalance_x408_firmware scalance_x300_firmware scalance_x414_firmware simatic_et_200sp_firmware simatic_s7-1500_firmware scalance_x200_firmware simatic_cp_1243-1_firmware +192 more products- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8895
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attack... Read more
Affected Products : backup_exec- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8892
Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3 allows remote attackers to inject arbitrary web script or HTML persistently via the name of an uploaded image.... Read more
Affected Products : tempo_box- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8852
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted remote source. The problem is that the length of data written is an arbitrary number found within the file.... Read more
Affected Products : sapcar- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8891
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.... Read more
Affected Products : lepton- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8890
The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3894
A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator by... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-8879
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.... Read more
Affected Products : dolibarr_erp\/crm- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7888
Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.... Read more
Affected Products : dolibarr_erp\/crm- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7887
Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7886
Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7698
A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via a malformed PDF document, possibly a consequence of an error in Gfx.cc in Xpdf 3.02.... Read more
Affected Products : swftools- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
3.8
LOWCVE-2017-4896
Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-4895
Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-1137
IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549.... Read more
Affected Products : websphere_application_server- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-1103
IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all availabl... Read more
Affected Products : rational_collaborative_lifecycle_management rational_quality_manager rational_team_concert- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9250
In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +4 more products- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2016-6037
IBM Rational Team Concert (RTC) is vulnerable to HTML injection. A remote attacker with project administrator privileges could send a project that contains malicious HTML code, which when the project is viewed, would be executed in the victim's Web browse... Read more
Affected Products : rational_collaborative_lifecycle_management rational_quality_manager rational_team_concert- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6035
IBM Rational Quality Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
Affected Products : rational_collaborative_lifecycle_management rational_quality_manager rational_team_concert- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-5889
IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 115085.... Read more
Affected Products : interact- Published: May. 10, 2017
- Modified: Apr. 20, 2025