Latest CVE Feed
-
6.1
MEDIUMCVE-2015-7565
Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, and 2.2.x before 2.2.1 allows remote attackers to inject arbitrary web sc... Read more
Affected Products : ember.js- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-6674
Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplete fix of CVE-2012-1836.... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2015-1839
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2015-1838
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2014-2710
Multiple cross-site scripting (XSS) vulnerabilities in Oliver (formerly Webshare) 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the (1) login page (index.php) or (2) login form (loginform-inc.php).... Read more
Affected Products : oliver- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2012-6697
InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop).... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7628
The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability).... Read more
Affected Products : smart_related_articles- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-7627
The "Smart related articles" extension 1.1 for Joomla! does not prevent direct requests to dialog.php (there is a missing _JEXEC check).... Read more
Affected Products : smart_related_articles- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7626
The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET Method).... Read more
Affected Products : smart_related_articles- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7748
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WSP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by adding a length check.... Read more
Affected Products : wireshark- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7747
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting additions to the protocol tree.... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7746
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding checks for the remaining length.... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7745
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SIGCOMP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-sigcomp.c by correcting a memory-size check.... Read more
Affected Products : wireshark- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7705
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the RPC over RDMA dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rpcrdma.c by correctly checking for going ... Read more
Affected Products : wireshark- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7704
In Wireshark 2.2.0 to 2.2.5, the DOF dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-dof.c by using a different integer data type and adjusting a return valu... Read more
Affected Products : wireshark- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7703
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-imap.c by calculating a line's end correctly.... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7702
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wbxml.c by adding length validation.... Read more
Affected Products : wireshark- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7701
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-bgp.c by using a different integer data type.... Read more
Affected Products : wireshark- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-7700
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by ensuring a nonzero record size.... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7284
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.... Read more
Affected Products : enterprise_backup- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025