Latest CVE Feed
-
6.1
MEDIUMCVE-2016-5737
The Gerrit configuration in the Openstack Puppet module for Gerrit (aka puppet-gerrit) improperly marks text/html as a safe mimetype, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a crafted review.... Read more
Affected Products : puppet-gerrit- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-5715
Open redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the redirect par... Read more
Affected Products : puppet_enterprise- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-3152
Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the firmware image.... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-3151
Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attacker... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-3150
Cross-site scripting (XSS) vulnerability in wallpaper.php in the Base Unit in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attack... Read more
Affected Products : clickshare_csc-1_firmware clickshare_cse-200_firmware clickshare_csc-1 clickshare_cse-200- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-3149
Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : clickshare_csm-1_firmware clickshare_csc-1_firmware clickshare_csc-1 clickshare_csm-1- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-10027
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "startt... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-6501
Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter.... Read more
Affected Products : puppet_enterprise- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8606
The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-8605
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode arg... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2016-8221
Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/output modules (IOMs), certain log files viewable by authenticated users may contain passwords for internal ad... Read more
Affected Products : xclarity_administrator- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7791
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to the website, then extract it by visiting '/install/index.php?install_sample=../../files/exploit', which le... Read more
Affected Products : exponent_cms- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7790
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which leads to arbitrary code execution.... Read more
Affected Products : exponent_cms- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0404
An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pr... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0403
An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privile... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0402
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be use... Read more
Affected Products : android- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0401
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate b... Read more
Affected Products : android- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0400
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be use... Read more
Affected Products : android- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0399
An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate b... Read more
Affected Products : android- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0397
An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitiv... Read more
Affected Products : android- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025