CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-7186

    Last Modified: 21 Nov 2024

    Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions.

    Published: 16 Feb 2018
    7.5
    High

    CVE-2017-18190

    Last Modified: 21 Nov 2024

    A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding. The localhost.localdomain name is often resolved via a DNS server (neither the OS nor the web browser is responsible for ensuring that localhost.localdomain is 127.0.0.1).

    Published: 16 Feb 2018
    5.3
    Medium

    CVE-2018-1107

    Last Modified: 21 Nov 2024

    It was discovered that the is-my-json-valid JavaScript library used an inefficient regular expression to validate JSON fields defined to have email format. A specially crafted JSON file could cause it to consume an excessive amount of CPU time when validated.

    Published: 16 Feb 2018
    9.8
    Critical

    CVE-2018-5767

    Last Modified: 21 Nov 2024

    An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.

    Published: 15 Feb 2018
    7.5
    High

    CVE-2018-6316

    Last Modified: 21 Nov 2024

    Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5807

    Last Modified: 21 Nov 2024

    A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

    Published: 15 Feb 2018
    7.5
    High

    CVE-2017-5808

    Last Modified: 21 Nov 2024

    A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

    Published: 15 Feb 2018
    5.5
    Medium

    CVE-2017-5809

    Last Modified: 21 Nov 2024

    A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5810

    Last Modified: 21 Nov 2024

    A remote sql injection vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

    Published: 15 Feb 2018
    7.5
    High

    CVE-2017-5811

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

    Published: 15 Feb 2018
    7.5
    High

    CVE-2017-5812

    Last Modified: 21 Nov 2024

    A remote sql information disclosure vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5815

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5816

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5817

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Published: 15 Feb 2018
    7.5
    High

    CVE-2017-5818

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5819

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5820

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5821

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5823

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-5824

    Last Modified: 21 Nov 2024

    An unauthenticated remote code execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-5825

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-5826

    Last Modified: 21 Nov 2024

    An authenticated remote code execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

    Published: 15 Feb 2018
    5.4
    Medium

    CVE-2017-5827

    Last Modified: 21 Nov 2024

    A reflected cross site scripting vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

    Published: 15 Feb 2018
    8.1
    High

    CVE-2017-5828

    Last Modified: 21 Nov 2024

    An arbitrary command execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

    Published: 15 Feb 2018
    7.8
    High

    CVE-2017-5829

    Last Modified: 21 Nov 2024

    An access restriction bypass vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-8957

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-8947

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE UCMDB version v10.10, v10.11, v10.20, v10.21, v10.22, v10.30, v10.31 was found.

    Published: 15 Feb 2018
    6.1
    Medium

    CVE-2017-8945

    Last Modified: 21 Nov 2024

    A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.

    Published: 15 Feb 2018
    8.3
    High

    CVE-2017-8946

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Aruba AirWave Glass version v1.0.0 and 1.0.1 was found.

    Published: 15 Feb 2018
    5.5
    Medium

    CVE-2017-8950

    Last Modified: 21 Nov 2024

    A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

    Published: 15 Feb 2018
    7.8
    High

    CVE-2017-8951

    Last Modified: 21 Nov 2024

    A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

    Published: 15 Feb 2018
    7.5
    High

    CVE-2017-8952

    Last Modified: 21 Nov 2024

    A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.

    Published: 15 Feb 2018
    5.4
    Medium

    CVE-2017-8953

    Last Modified: 21 Nov 2024

    A Remote Cross-Site Scripting (XSS) vulnerability in HPE LoadRunner v12.53 and earlier and HPE Performance Center version v12.53 and earlier was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-8954

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

    Published: 15 Feb 2018
    7.5
    High

    CVE-2017-8955

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-8956

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-8960

    Last Modified: 21 Nov 2024

    An Authentication Bypass vulnerability in HPE MSA 1040 and MSA 2040 SAN Storage IN version GL220P008 and earlier was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-8961

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-8962

    Last Modified: 21 Nov 2024

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-8963

    Last Modified: 21 Nov 2024

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-8964

    Last Modified: 21 Nov 2024

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

    Published: 15 Feb 2018
    8.8
    High

    CVE-2017-8965

    Last Modified: 21 Nov 2024

    A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

    Published: 15 Feb 2018
    5.7
    Medium

    CVE-2017-8969

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found.

    Published: 15 Feb 2018
    5.3
    Medium

    CVE-2017-8970

    Last Modified: 21 Nov 2024

    A remote unauthenticated disclosure of information vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

    Published: 15 Feb 2018
    4.3
    Medium

    CVE-2017-8971

    Last Modified: 21 Nov 2024

    A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

    Published: 15 Feb 2018
    4.3
    Medium

    CVE-2017-8972

    Last Modified: 21 Nov 2024

    A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

    Published: 15 Feb 2018
    4.3
    Medium

    CVE-2017-8973

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.

    Published: 15 Feb 2018
    7.5
    High

    CVE-2017-8982

    Last Modified: 21 Nov 2024

    A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.

    Published: 15 Feb 2018
    9.8
    Critical

    CVE-2017-8976

    Last Modified: 21 Nov 2024

    A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.

    Published: 15 Feb 2018
    9.1
    Critical

    CVE-2017-8977

    Last Modified: 21 Nov 2024

    A Remote Denial of Service vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.

    Published: 15 Feb 2018