Latest CVE Feed
-
9.8
CRITICALCVE-2016-3147
Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large packet.... Read more
Affected Products : landesk_management_suite- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-2783
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet f... Read more
Affected Products : vsp_operating_system_software- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-2242
Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.... Read more
Affected Products : exponent_cms- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-1925
Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow.... Read more
Affected Products : lha_for_unix- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-1417
Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse tcapi.dll that is located in the same folder on a remote file share as a pcap file that is be... Read more
Affected Products : snort- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-1281
Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibly other products allows local users to execute arbitrary code with administrator privileges and conduct DLL hijacking attacks via a Tro... Read more
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-0769
Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands v... Read more
Affected Products : eshop_plugin- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-0765
Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.... Read more
Affected Products : eshop_plugin- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8972
Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated when in UCI mode.... Read more
Affected Products : chess- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-8971
Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the terminal, a similar issue to CVE-2003-0063.... Read more
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8862
mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.... Read more
Affected Products : mustache.js- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8861
The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.... Read more
Affected Products : handlebars.js- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-8860
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.... Read more
Affected Products : node.js- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2015-8859
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.... Read more
Affected Products : send- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-8858
The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."... Read more
Affected Products : uglifyjs- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8857
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improper... Read more
Affected Products : uglifyjs- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8856
Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary web script or HTML via a crafted file or directory name.... Read more
Affected Products : serve-index- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-8855
The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."... Read more
Affected Products : node.js- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-8854
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular expression denial of service (ReDoS... Read more
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-8315
The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."... Read more
Affected Products : ms- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025