Latest CVE Feed
-
6.5
MEDIUMCVE-2017-2686
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and access sensitive information.... Read more
Affected Products : ruggedcom_rox_i- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7297
Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.... Read more
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6807
Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent ... Read more
Affected Products : ambari- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8749
Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.... Read more
Affected Products : camel- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2016-8031
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input file.... Read more
Affected Products : anti-malware_scan_engine- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-6440
VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8884
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of an in... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10152
The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.... Read more
Affected Products : hesiod- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-7277
The TCP stack in the Linux kernel through 4.10.6 mishandles the SCM_TIMESTAMPING_OPT_STATS feature, which allows local users to obtain sensitive information from the kernel's internal socket data structures or cause a denial of service (out-of-bounds read... Read more
Affected Products : linux_kernel- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-0882
Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC.... Read more
Affected Products : gitlab- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-0881
An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user to subscribe to a private stream that should have required an invitation from... Read more
Affected Products : zulip_server- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-9473
Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to trick a victim by displaying a malicious page for legitimate domain names.... Read more
Affected Products : browser- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9472
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulnerable to a reflected XSS attack via the dbHost, dbUser, and possibly other parameters. It has to be noted that the window for such attac... Read more
Affected Products : revive_adserver- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
3.1
LOWCVE-2016-9471
Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. Usernames weren't properly sanitised when creating users on a Revive Adserver instance. Especially, control characters were not filtered, allowing apparently identical username... Read more
Affected Products : revive_adserver- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-9470
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's machi... Read more
Affected Products : revive_adserver- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2016-9469
Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects on a GitLab instance. For GitLab instances with publicly available projects this vulnerability could be e... Read more
Affected Products : gitlab- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9468
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential misrepr... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9467
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake ... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9466
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the Nextcloud/ownCloud server. Due to an endpoint where an at... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9465
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of images stored within a vCard. Due to... Read more
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025