Latest CVE Feed
-
7.2
HIGHCVE-2016-9196
A vulnerability in login authentication management in Cisco Aironet 1800, 2800, and 3800 Series Access Point platforms could allow an authenticated, local attacker to gain unrestricted root access to the underlying Linux operating system. The root Linux s... Read more
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9195
A vulnerability in RADIUS Change of Authorization (CoA) request processing in the Cisco Wireless LAN Controller (WLC) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition by disconnecting a single connection. This v... Read more
Affected Products : wireless_lan_controller- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7579
inc/PMF/Faq.php in phpMyFAQ before 2.9.7 has XSS in the question field.... Read more
Affected Products : phpmyfaq- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-2387
The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : apple_music- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7578
Multiple heap-based buffer overflows in parser.c in libming 0.4.7 allow remote attackers to cause a denial of service (listswf application crash) or possibly have unspecified other impact via a crafted SWF file. NOTE: this issue exists because of an incom... Read more
Affected Products : libming- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7577
XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.... Read more
Affected Products : uc-httpd- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7570
PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension.... Read more
Affected Products : pivotx- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-1000307
Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to inject arbitrary web script or HTML via (1) profile_desc, about_me, schools, occupation, companies, hobbies, fav_movies, fav_music, fav_b... Read more
Affected Products : clipbucket- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-4673
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the collection_description parameter to upload/manage_collections.php in an add_new action or the (2)... Read more
Affected Products : clipbucket- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7576
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting t... Read more
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7575
Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the application-protection password via a \x00\x01\x00\x00\x00\x05\x01\x5a\x00\x03\x00 request to the Modbus port (502/tcp). Subsequently the application may be arbit... Read more
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7574
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-key vulnerability. The Project Protection feature is used to prevent unauthorized users from opening an XML protected project file, by pr... Read more
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8735
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this... Read more
Affected Products : ubuntu_linux debian_linux agile_engineering_data_management oncommand_insight oncommand_shift mysql_enterprise_monitor tomcat hospitality_guest_access jboss_enterprise_web_server agile_plm +9 more products- Actively Exploited
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6809
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.... Read more
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8965
Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController se... Read more
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-4964
Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the director, aka a "CPI code injection vulnerability."... Read more
Affected Products : bosh_azure_cpi- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-5349
The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure applications inside Qualcomm Secure Execution Environment (QSEE) only write to legitimate memory ranges related to the QSEE secure applic... Read more
Affected Products : android- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-7572
The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subject to a race condition (time of check, time of use). With this authorizati... Read more
Affected Products : backintime- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-3834
A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express Software could allow an unauthenticated, remote attacker to take complete control of an affected device. The vulnerability is due to th... Read more
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3832
A vulnerability in the web management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a missing inter... Read more
Affected Products : wireless_lan_controller wireless_lan_controller_firmware wireless_lan_controller- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025