Latest CVE Feed
-
7.5
HIGHCVE-2016-8207
A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read arbitrary files including files with sensitive user information.... Read more
Affected Products : network_advisor- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-8206
A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to write to arbitrary files, and consequently delete the files.... Read more
Affected Products : network_advisor- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-8205
A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be execu... Read more
Affected Products : network_advisor- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-8204
A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.... Read more
- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2016-8201
A CSRF vulnerability in Brocade Virtual Traffic Manager versions released prior to and including 11.0 could allow an attacker to trick a logged-in user into making administrative changes on the traffic manager cluster.... Read more
Affected Products : virtual_traffic_manager- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5476
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.... Read more
Affected Products : serendipity- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5475
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.... Read more
Affected Products : serendipity- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5474
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.... Read more
Affected Products : serendipity- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5473
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user_prefs.lua, admin/delete_user.lua, and admin/password_re... Read more
Affected Products : ntopng- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2016-10142
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vendors.) The security implications of IP fragmentation have been discussed at ... Read more
Affected Products : ipv6- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2010-5327
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.... Read more
Affected Products : liferay_portal- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0398
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Produc... Read more
Affected Products : android- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9813
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9812
The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section.... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-9811
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.... Read more
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9810
The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref ca... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-9809
Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9808
The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted series of skip and count pairs.... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9807
The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9312
ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.... Read more
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025