Latest CVE Feed
-
8.8
HIGHCVE-2017-6087
EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3) ownDisown function in module/monitoring_ged/ged_functi... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5869
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.... Read more
Affected Products : nuxeo- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-5644
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.... Read more
Affected Products : poi- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10149
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2015-8678
The ION driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 and Mate S smartphones with softw... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.... Read more
Affected Products : qemu- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6369
Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-6507
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intende... Read more
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5199
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.... Read more
Affected Products : log_and_event_manager- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5198
SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.... Read more
Affected Products : log_and_event_manager- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7251
A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the "pi-develop/www/script/editor/markitup/preview/markdown.php" URL. An attacker could ex... Read more
Affected Products : pi- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7250
A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient filtration of user-supplied data (action) passed to the 'Gazelle-master/sections/tools/finances/bitcoin_balance.php' URL. An attacker co... Read more
Affected Products : gazelle- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7249
Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (action, userid) passed to the 'Gazelle-master/sections/tools/data/ocelot_info.php' URL. An at... Read more
Affected Products : gazelle- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7248
A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient filtration of user-supplied data (type) passed to the 'Gazelle-master/sections/better/transcode.php' URL. An attacker could execute arbi... Read more
Affected Products : gazelle- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7247
Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (torrents, size) passed to the 'Gazelle-master/sections/tools/managers/multiple_freeleech.php'... Read more
Affected Products : gazelle- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7246
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file.... Read more
Affected Products : pcre- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7245
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 4) or possibly have unspecified other impact via a crafted file.... Read more
Affected Products : pcre- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7244
The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.... Read more
Affected Products : pcre- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6950
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.... Read more
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.6
MEDIUMCVE-2017-6911
USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and password in simple usb.xml. An attacker with physical access to the system can modify the file according his own requirements that may aid in ... Read more
Affected Products : usb_pratirodh- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025