Latest CVE Feed
-
4.3
MEDIUMCVE-2016-9978
IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.... Read more
Affected Products : curam_social_program_management- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-8923
IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536.... Read more
Affected Products : curam_social_program_management- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-5401
Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web page.... Read more
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-3734
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum... Read more
Affected Products : moodle- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-3733
The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.... Read more
Affected Products : moodle- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-3732
The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.... Read more
Affected Products : moodle- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-3731
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.... Read more
Affected Products : moodle- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-3729
The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.... Read more
Affected Products : moodle- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2016-1161
Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).... Read more
Affected Products : password_manager_pro- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-8285
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.... Read more
Affected Products : total_security- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-5160
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.... Read more
Affected Products : wonderware_intouch_access_anywhere- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5158
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specifie... Read more
Affected Products : wonderware_intouch_access_anywhere- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5156
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems o... Read more
Affected Products : wonderware_intouch_access_anywhere- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5183
NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.... Read more
Affected Products : access_manager- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2806
An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulnerability was confirmed on versions 1... Read more
Affected Products : perceptive_document_filters- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-2784
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library, can cause an i... Read more
Affected Products : mbed_tls- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2016-8721
An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially crafted web form input can cause an OS Command Injection resulting in complete co... Read more
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-7540
coders/rgf.c in ImageMagick before 6.9.4-10 allows remote attackers to cause a denial of service (assertion failure) by converting an image to rgf format.... Read more
Affected Products : imagemagick- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-7538
coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.... Read more
Affected Products : imagemagick- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-7536
magick/profile.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via a crafted profile.... Read more
Affected Products : imagemagick- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025