Latest CVE Feed
-
10.0
CRITICALCVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.... Read more
Affected Products : qemu- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6369
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-6507
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intende... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5199
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.... Read more
Affected Products : log_and_event_manager- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5198
SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.... Read more
Affected Products : log_and_event_manager- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7251
A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the "pi-develop/www/script/editor/markitup/preview/markdown.php" URL. An attacker could ex... Read more
Affected Products : pi- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7250
A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient filtration of user-supplied data (action) passed to the 'Gazelle-master/sections/tools/finances/bitcoin_balance.php' URL. An attacker co... Read more
Affected Products : gazelle- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7249
Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (action, userid) passed to the 'Gazelle-master/sections/tools/data/ocelot_info.php' URL. An at... Read more
Affected Products : gazelle- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7248
A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient filtration of user-supplied data (type) passed to the 'Gazelle-master/sections/better/transcode.php' URL. An attacker could execute arbi... Read more
Affected Products : gazelle- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7247
Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (torrents, size) passed to the 'Gazelle-master/sections/tools/managers/multiple_freeleech.php'... Read more
Affected Products : gazelle- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7246
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file.... Read more
Affected Products : pcre- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7245
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 4) or possibly have unspecified other impact via a crafted file.... Read more
Affected Products : pcre- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7244
The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.... Read more
Affected Products : pcre- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6950
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.... Read more
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.6
MEDIUMCVE-2017-6911
USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in ... Read more
Affected Products : usb_pratirodh- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6895
USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml.... Read more
Affected Products : usb_pratirodh- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6517
Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to lo... Read more
Affected Products : skype- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-8687
Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceTypeID parameter to DeviceType/getD... Read more
Affected Products : motive_home_device_manager- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2015-8628
The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 allow remote attackers to ... Read more
Affected Products : mediawiki- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2015-8627
MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly normalize IP addresses containing zero-padded octets, which might allow remote attackers to bypass intended access restrictions by using an IP a... Read more
Affected Products : mediawiki- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025