Latest CVE Feed
-
8.8
HIGHCVE-2017-7647
SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.... Read more
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7646
SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.... Read more
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8237
Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.... Read more
Affected Products : updates- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8235
Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with elevated privileges.... Read more
Affected Products : customer_care_software_development_kit- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10323
Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command.... Read more
Affected Products : photo_station- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-10322
Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php.... Read more
Affected Products : photo_station- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7625
In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.... Read more
Affected Products : fiyo_cms- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7624
The iw_read_bmp_file function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to consume an amount of available memory via a crafted file.... Read more
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7623
The iwmiffr_convert_row32 function in imagew-miff.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.... Read more
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7622
dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the function through D-Bus. Anybody can change the grub config, even to append some arg... Read more
Affected Products : deepin_desktop_environment- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5041
dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a debugging information entry using DWARF5 and without a DW_AT_name.... Read more
Affected Products : libdwarf- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.0
MEDIUMCVE-2017-7377
The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.... Read more
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-7345
NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Method Invocation (aka JMX RMI) service to the network, which allows remote attackers to obtain s... Read more
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7239
Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.... Read more
Affected Products : ninka- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7185
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via... Read more
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5988
NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vectors.... Read more
Affected Products : clustered_data_ontap- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5983
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Ja... Read more
Affected Products : jira- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-5607
Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace... Read more
Affected Products : splunk- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6879
The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call with more than one Key_Usage set in the enum value.... Read more
Affected Products : botan- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6878
The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to have unspecified impact via vectors related to undefined behavior, as demonstrated on 32-bit ARM systems compiled by Clang.... Read more
Affected Products : botan- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025