Latest CVE Feed
-
10.0
HIGHCVE-2016-10308
Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to t... Read more
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10307
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This acco... Read more
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10306
Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.... Read more
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10305
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default pas... Read more
Affected Products : apex_plus_firmware apex_firmware apex_lynx_firmware apex_orion_firmware giga_firmware giga_lynx_firmware giga_orion_firmware giga_plus_firmware giga_pro_firmware stratalink_pro_firmware +12 more products- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7310
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary c... Read more
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-4980
EMC Isilon OneFS is affected by a path traversal vulnerability that may potentially be exploited by attackers to compromise the affected system. Affected versions are 7.1.0 - 7.1.1.10, 7.2.0 - 7.2.1.3, and 8.0.0 - 8.0.0.1.... Read more
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-4977
EMC RSA Archer Security Operations Management with RSA Unified Collector Framework versions prior to 1.3.1.52 contain a sensitive information disclosure vulnerability that could potentially be exploited by malicious users to compromise an affected system.... Read more
Affected Products : rsa_archer_security_operations_management- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7308
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain... Read more
Affected Products : linux_kernel- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7258
HTTP Exploit in eMLi Portal in AuroMeera Technometrix Pvt. Ltd. eMLi allows an Attacker to View Restricted Information or (even more seriously) execute powerful commands on the web server which can lead to a full compromise of the system via Directory Pat... Read more
Affected Products : emli- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-5226
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.... Read more
Affected Products : bubblewrap- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2016-6349
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.... Read more
Affected Products : oci-register-machine- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4976
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.... Read more
Affected Products : ambari- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-2379
The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging knowledge of client registration codes or (2) gain login access by eavesdropping on login messages and re-usin... Read more
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-3582
In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.... Read more
Affected Products : ambari- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7304
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of missing a check (in the copy_special_section_fields function) for an invalid sh_link field before attemptin... Read more
Affected Products : binutils- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7303
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 4) because of missing a check (in the find_link function) for null headers before attempting to match them. This vulnerab... Read more
Affected Products : binutils- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7302
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swap_std_reloc_out function in bfd/aoutx.h that is vulnerable to an invalid read (of size 4) because of missing checks for relocs that could not be recognise... Read more
Affected Products : binutils- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7301
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that has an off-by-one vulnerability because it does not carefully check the string offset. The vulnerability ... Read more
Affected Products : binutils- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7300
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that is vulnerable to a heap-based buffer over-read (off-by-one) because of an incomplete check for invalid st... Read more
Affected Products : binutils- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7299
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before t... Read more
Affected Products : binutils- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025