Latest CVE Feed
-
5.9
MEDIUMCVE-2016-6882
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information by conducting a Lenstra side-channel attack.... Read more
Affected Products : matrixssl- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8815
Multiple cross-site scripting (XSS) vulnerabilities in Umbraco before 7.4.0 allow remote attackers to inject arbitrary web script or HTML via the name parameter to (1) the media page, (2) the developer data edit page, or (3) the form page.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-8814
Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the templates.asmx.cs file.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2015-8813
The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5867
ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of service (server hang and logfile flooding) via a one bit BMP file.... Read more
Affected Products : owncloud- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-5866
The autocomplete feature in the E-Mail share dialog in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : owncloud- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-5865
The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user na... Read more
Affected Products : owncloud- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5836
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free.... Read more
Affected Products : libplist- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5835
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.... Read more
Affected Products : libplist- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-5834
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.... Read more
Affected Products : libplist- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5833
Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : revive_adserver- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5832
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.... Read more
Affected Products : revive_adserver- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5831
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.... Read more
Affected Products : revive_adserver- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5830
Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.... Read more
Affected Products : revive_adserver- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5616
Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5615
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5614
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.... Read more
Affected Products : cpanel- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5613
Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5571
Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to redirect users to ... Read more
Affected Products : flexnet_publisher- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5356
Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).... Read more
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025