Latest CVE Feed
-
4.3
MEDIUMCVE-2016-6094
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2016-6092
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-3020
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content validation. By persuading a victim to open specially-crafted content, an attacker could exploit this vuln... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7400
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, o... Read more
Affected Products : exponent_cms- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-7164
The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via a crafted GZIP response.... Read more
Affected Products : libtorrent- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6199
ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.... Read more
Affected Products : gradle- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6175
Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.... Read more
Affected Products : php-gettext- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6131
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.... Read more
Affected Products : libiberty- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-2781
chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.... Read more
Affected Products : coreutils- Published: Feb. 07, 2017
- Modified: Jun. 09, 2025
-
7.8
HIGHCVE-2016-2779
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.... Read more
Affected Products : util-linux- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-2539
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a cra... Read more
Affected Products : atutor- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-1504
dhcpcd before 6.10.0 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to the option length.... Read more
Affected Products : dhcpcd- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8608
The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive letter or (2) pInName argument.... Read more
Affected Products : perl- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-5677
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file.... Read more
Affected Products : freebsd- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10044
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup syst... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2014-9914
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during m... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5677
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.... Read more
Affected Products : html_ajax- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-5595
A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being passed to readfile(), which allows an authenticated attacker to read local system files (e.g., /etc/passwd)... Read more
Affected Products : zoneminder- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5368
ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a maliciou... Read more
Affected Products : zoneminder- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5367
Multiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, which allows a remote attacker to execute malicious scripts within an authenticated client's brow... Read more
Affected Products : zoneminder- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025