Latest CVE Feed
-
7.5
HIGHCVE-2017-7957
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") ca... Read more
- Published: Apr. 29, 2017
- Modified: May. 23, 2025
-
9.0
HIGHCVE-2017-7981
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an ... Read more
- Published: Apr. 29, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6553
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon.... Read more
Affected Products : privilege_manager_for_unix- Published: Apr. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7945
The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows... Read more
Affected Products : pan-os- Published: Apr. 29, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7644
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PA... Read more
Affected Products : pan-os- Published: Apr. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6250
NVIDIA GeForce Experience contains a vulnerability in NVIDIA Web Helper.exe, where untrusted script execution may lead to violation of application execution policy and local code execution.... Read more
Affected Products : geforce_experience- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8593
Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8592
log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8591
log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8590
log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8589
log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2016-8588
The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2016-8587
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sen... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8586
detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8585
admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter.... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8584
Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.... Read more
Affected Products : threat_discovery_appliance- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1194
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.... Read more
Affected Products : websphere_application_server- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1141
IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907.... Read more
Affected Products : insights_foundation_for_energy- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2156
Untrusted search path vulnerability in Vivaldi installer for Windows prior to version 1.7.735.48 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.... Read more
Affected Products : vivaldi_installer_for_windows- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2155
Buffer overflow in Hoozin Viewer 2, 3, 4.1.5.15 and earlier, 5.1.2.13 and earlier, and 6.0.3.09 and earlier allows remote attackers to execute arbitrary code via specially crafted webpage.... Read more
Affected Products : hoozin_viewer- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025