Latest CVE Feed
-
7.8
HIGHCVE-2017-6401
An issue was discovered in Veritas NetBackup before 8.0 and NetBackup Appliance before 3.0. Local arbitrary command execution can occur when using bpcd and bpnbat.... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6400
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged command execution on NetBackup Server and Client can occur (on the local system).... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6399
An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged remote command execution on NetBackup Server and Client (on the server or a connected client) can occur.... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6397
An issue was discovered in FlightAirMap v1.0-beta.10. The vulnerability exists due to insufficient filtration of user-supplied data in multiple parameters passed to several *-sub-menu.php pages. An attacker could execute arbitrary HTML and script code in ... Read more
Affected Products : flightairmap- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6396
An issue was discovered in WPO-Foundation WebPageTest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "webpagetest-master/www/compare-cf.php" URL. An attacker could execute arbitrary HTML and script code in... Read more
Affected Products : webpagetest- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6395
An issue was discovered in HashOver 2.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the 'hashover/scripts/widget-output.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the con... Read more
Affected Products : hashover- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6394
Multiple Cross-Site Scripting (XSS) issues were discovered in OpenEMR 5.0.0 and 5.0.1-dev. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to the "openemr-master/gacl/admin/object_search.php" URL (section_value; src_f... Read more
Affected Products : openemr- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6393
An issue was discovered in NagVis 1.9b12. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "nagvis-master/share/userfiles/gadgets/std_table.php" URL. An attacker could execute arbitrary HTML and script code in a ... Read more
Affected Products : nagvis- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6392
An issue was discovered in Kaltura server Lynx-12.11.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "server-Lynx-12.11.0/admin_console/web/tools/XmlJWPlayer.php" URL. An attacker could execute arbitrary HTML... Read more
Affected Products : kaltura_server- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6391
An issue was discovered in Kaltura server Lynx-12.11.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "admin_console/web/tools/SimpleJWPlayer.php" URL, the "admin_console/web/tools/AkamaiBroadcaster.php" URL, ... Read more
Affected Products : kaltura_server- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6390
An issue was discovered in whatanime.ga before c334dd8499a681587dd4199e90b0aa0eba814c1d. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "whatanime.ga-master/index.php" URL. An attacker could execute arbitrary H... Read more
Affected Products : whatanime.ga- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6384
Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service. This is fixed in 7.2.8.... Read more
Affected Products : atheme- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-6062
The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "OIDCUnAuthAction pass" configuration, which allows remote a... Read more
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-8994
An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache enabled. With 5.x after 5.6.28 or 7.x after 7.0.13, the issue is resolved in a non-default configuration with the opcache.validate_permi... Read more
Affected Products : php- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6415
The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DEX file.... Read more
Affected Products : radare2- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6387
The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DEX file.... Read more
Affected Products : radare2- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6319
The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file.... Read more
Affected Products : radare2- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-10228
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input ... Read more
Affected Products : glibc- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8233
Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form that could be viewed by a non-privileged user.... Read more
Affected Products : xclarity_administrator- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3826
A vulnerability in the Stream Control Transmission Protocol (SCTP) decoder of the Cisco NetFlow Generation Appliance (NGA) with software before 1.1(1a) could allow an unauthenticated, remote attacker to cause the device to hang or unexpectedly reload, cau... Read more
- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025