Latest CVE Feed
-
5.5
MEDIUMCVE-2016-3020
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content validation. By persuading a victim to open specially-crafted content, an attacker could exploit this vuln... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7400
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, o... Read more
Affected Products : exponent_cms- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-7164
The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via a crafted GZIP response.... Read more
Affected Products : libtorrent- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6199
ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.... Read more
Affected Products : gradle- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6175
Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.... Read more
Affected Products : php-gettext- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6131
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.... Read more
Affected Products : libiberty- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-2781
chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.... Read more
Affected Products : coreutils- Published: Feb. 07, 2017
- Modified: Jun. 09, 2025
-
7.8
HIGHCVE-2016-2779
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.... Read more
Affected Products : util-linux- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-2539
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a cra... Read more
Affected Products : atutor- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-1504
dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.... Read more
Affected Products : dhcpcd- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8608
The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.... Read more
Affected Products : perl- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-5677
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file.... Read more
Affected Products : freebsd- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10044
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup syst... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2014-9914
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during m... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5677
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.... Read more
Affected Products : html_ajax- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-5595
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd)... Read more
Affected Products : zoneminder- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5368
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a maliciou... Read more
Affected Products : zoneminder- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5367
Multiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, which allows a remote attacker to execute malicious scripts within an authenticated client's brow... Read more
Affected Products : zoneminder- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9772
OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2) fileserver vice partition, or (3) certain RPC responses.... Read more
Affected Products : openafs- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9532
Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.... Read more
- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025