Latest CVE Feed
-
6.1
MEDIUMCVE-2017-5615
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5614
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.... Read more
Affected Products : cpanel- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5613
Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5571
Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to redirect users to ... Read more
Affected Products : flexnet_publisher- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5356
Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5196
Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via vectors involving strings that are not UTF8.... Read more
Affected Products : irssi- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5195
Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ANSI x8 color code.... Read more
Affected Products : irssi- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5194
Use-after-free vulnerability in Irssi before 0.8.21 allows remote attackers to cause a denial of service (crash) via an invalid nick message.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5193
The nickcmp function in Irssi before 0.8.21 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a message without a nick.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-2290
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. ... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-10206
Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a crafted user ac... Read more
Affected Products : zoneminder- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10205
Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie.... Read more
Affected Products : zoneminder- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10204
SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.... Read more
Affected Products : zoneminder- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-10203
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the name when creating a new monitor.... Read more
Affected Products : zoneminder- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-10202
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path info to index.php.... Read more
Affected Products : zoneminder- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-10201
Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter in a download log request to index.php.... Read more
Affected Products : zoneminder- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10194
The festivaltts4r gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the (1) to_speech or (2) to_mp3 method in lib/festivaltts4r/festival4r.rb.... Read more
Affected Products : festivaltts4r- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10193
The espeak-ruby gem before 1.0.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the speak, save, bytes or bytes_wav method in lib/espeak/speech.rb.... Read more
Affected Products : espeak-ruby- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.0
CRITICALCVE-2016-10127
PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.... Read more
Affected Products : pysaml2- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2015-2877
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAI... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025