Latest CVE Feed
-
9.3
HIGHCVE-2017-0544
An elevation of privilege vulnerability in CameraBase could enable a local malicious application to execute arbitrary code. This issue is rated as High because it is a local arbitrary code execution in a privileged process. Product: Android. Versions: 4.4... Read more
Affected Products : android- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0543
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code ... Read more
Affected Products : android- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0542
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code ... Read more
Affected Products : android- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0541
A remote code execution vulnerability in sonivox in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code... Read more
Affected Products : android- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0540
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code... Read more
Affected Products : android- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0539
A remote code execution vulnerability in libhevc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code... Read more
Affected Products : android- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0538
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code ... Read more
Affected Products : android- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0462
An elevation of privilege vulnerability in the Qualcomm Seemp driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0454
An elevation of privilege vulnerability in the Qualcomm audio driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-7786
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6.5.... Read more
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2007-6760
Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCCOOKIE cookie.... Read more
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2007-6759
Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCRABBIT cookie.... Read more
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7586
In libsndfile before 1.0.28, an error in the "header_read()" function (common.c) when handling ID3 tags can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.... Read more
Affected Products : libsndfile- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7585
In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.... Read more
Affected Products : libsndfile- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7584
Memory Corruption Vulnerability in Foxit PDF Toolkit before 2.1 allows an attacker to cause Denial of Service & Remote Code Execution when a victim opens a specially crafted PDF file.... Read more
Affected Products : foxit_pdf_toolkit- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUM- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7581
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.... Read more
Affected Products : news_system- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-6805
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.... Read more
Affected Products : ignite- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
6.9
MEDIUMCVE-2017-6606
A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to execute arbitrary commands on the underlying operating system with the privileges of the root user. More In... Read more
Affected Products : ios_xe- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6604
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability affects the following Cisco products running Cisco... Read more
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025