CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2017-13205

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64550583.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13206

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (aacdec). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-65025048.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13207

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Android media framework (stagefright mpeg4writer). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37564426.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13210

    Last Modified: 21 Nov 2024

    In CameraDeviceClient::submitRequestList of CameraDeviceClient.cpp, there is an out-of-bounds write if metadataSize is too small. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67782345.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13211

    Last Modified: 21 Nov 2024

    In bta_scan_results_cb_impl of btif_ble_scanner.cc, there is possible resource exhaustion if a large number of repeated BLE scan results are received. This could lead to a remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0. Android ID: A-65174158.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13212

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the Android system (systemui). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62187985.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13213

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the Broadcom bcmdhd driver. Product: Android. Versions: Android kernel. Android ID: A-63374465. References: B-V2017081501.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13217

    Last Modified: 21 Nov 2024

    In DisplayFtmItem in the bootloader, there is an out-of-bounds write due to reading a string without verifying that it's null-terminated. This could lead to a secure boot bypass and a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-68269077.

    Published: 12 Jan 2018
    4.7
    Medium

    CVE-2017-13218

    Last Modified: 21 Nov 2024

    Access to CNTVCT_EL0 in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear could be used for side channel attacks and this could lead to local information disclosure with no additional execution privileges needed in FSM9055, IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, QCA4531, QCA9980, QCN5502, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13219

    Last Modified: 21 Nov 2024

    A denial of service vulnerability in the Upstream kernel synaptics touchscreen controller. Product: Android. Versions: Android kernel. Android ID: A-62800865.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-13222

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Upstream kernel kernel. Product: Android. Versions: Android kernel. Android ID: A-38159576.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13225

    Last Modified: 21 Nov 2024

    In libMtkOmxVdec.so there is a possible heap buffer overflow. This could lead to a remote elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38308024. References: M-ALPS03495789.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-13226

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the MediaTek mtk. Product: Android. Versions: Android kernel. Android ID: A-32591194. References: M-ALPS03149184.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-0855

    Last Modified: 21 Nov 2024

    In MPEG4Extractor.cpp, there are several places where functions return early without cleaning up internal buffers which could lead to memory leaks. This could lead to remote denial of service of a critical system process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64452857.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2015-9246

    Last Modified: 21 Nov 2024

    An issue was discovered in Skybox Platform before 7.5.201. Remote Unauthenticated Code Execution exists via a WAR archive containing a JSP file. The WAR file is sent to /skyboxview-softwareupdate/services/CollectorSoftwareUpdate and the JSP file is reached at /opt/skyboxview/thirdparty/jboss/server/web/work/jboss.web/localhost.

    Published: 12 Jan 2018
    5.4
    Medium

    CVE-2015-9247

    Last Modified: 21 Nov 2024

    An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyboxview/webservice/services/VersionRepositoryWebService via a soapenv:Body element, or in the status parameter to login.html.

    Published: 12 Jan 2018
    5.4
    Medium

    CVE-2015-9248

    Last Modified: 21 Nov 2024

    An issue was discovered in Skybox Platform before 7.5.201. Stored cross-site scripting vulnerabilities exist in the title, Comments, or Description field to /skyboxview/webskybox/tickets in Change Manager.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2015-9249

    Last Modified: 21 Nov 2024

    An issue was discovered in Skybox Platform before 7.5.201. SQL Injection exists in /skyboxview/webservice/services/VersionWebService via a soapenv:Body element.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2015-9250

    Last Modified: 21 Nov 2024

    An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmentdownload and /skyboxview/webskybox/filedownload via the tempFileName parameter.

    Published: 12 Jan 2018
    5.5
    Medium

    CVE-2018-5650

    Last Modified: 21 Nov 2024

    In Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted lrz file.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-16737

    Last Modified: 21 Nov 2024

    An issue was discovered in WECON Technology LEVI Studio HMI Editor v1.8.29 and prior. A specially-crafted malicious file may be able to cause a heap-based buffer overflow vulnerability when opened by a user.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-14030

    Last Modified: 21 Nov 2024

    An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.

    Published: 12 Jan 2018
    5.3
    Medium

    CVE-2017-16741

    Last Modified: 21 Nov 2024

    An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to use Monitor Mode on the device to read diagnostic information.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-16739

    Last Modified: 21 Nov 2024

    An issue was discovered in WECON Technology LEVI Studio HMI Editor v1.8.29 and prior. Specially-crafted malicious files may be able to cause stack-based buffer overflow vulnerabilities, which may allow remote code execution.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2017-16743

    Last Modified: 21 Nov 2024

    An Improper Authorization issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32. A remote unauthenticated attacker may be able to craft special HTTP requests allowing an attacker to bypass web-service authentication allowing the attacker to obtain administrative privileges on the device.

    Published: 12 Jan 2018
    6.1
    Medium

    CVE-2016-10705

    Last Modified: 21 Nov 2024

    The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.

    Published: 12 Jan 2018
    6.1
    Medium

    CVE-2016-10706

    Last Modified: 21 Nov 2024

    The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2018-5315

    Last Modified: 21 Nov 2024

    The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2015-2298

    Last Modified: 21 Nov 2024

    node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper substring check when exporting a padID.

    Published: 12 Jan 2018
    5.9
    Medium

    CVE-2015-2981

    Last Modified: 21 Nov 2024

    The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2014-7952

    Last Modified: 21 Nov 2024

    The backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code by leveraging failure to filter application data streams.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2014-6436

    Last Modified: 21 Nov 2024

    Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.

    Published: 12 Jan 2018
    8.8
    High

    CVE-2016-0324

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to execute arbitrary code with administrator privileges via unspecified vectors. IBM X-Force ID: 111640.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2014-6435

    Last Modified: 21 Nov 2024

    cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows remote attackers to cause a denial of service (WAN connectivity reset) via a direct request.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2014-6437

    Last Modified: 21 Nov 2024

    Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors involving the ROM file.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2015-3888

    Last Modified: 21 Nov 2024

    Jolla Sailfish OS before 1.1.2.16 allows remote attackers to spoof phone numbers and trigger calls to arbitrary numbers via spaces in a tel: URL.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2016-0327

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors. IBM X-Force ID: 111643.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2016-0332

    Last Modified: 21 Nov 2024

    IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach. IBM X-Force ID: 111695.

    Published: 12 Jan 2018
    8.8
    High

    CVE-2016-0335

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors. IBM X-Force ID: 111736.

    Published: 12 Jan 2018
    5.4
    Medium

    CVE-2016-0336

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 111737.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2017-16885

    Last Modified: 21 Nov 2024

    Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version of device, Firmware ID, Connected users to device along their MAC Addresses, etc.

    Published: 12 Jan 2018
    8.8
    High

    CVE-2017-16886

    Last Modified: 21 Nov 2024

    The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2017-16887

    Last Modified: 21 Nov 2024

    The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2017-17970

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php; the (2) season_id parameter to themes/flixer/ajax/load_season.php; the (3) movie_id parameter to themes/flixer/ajax/get_rating.php; the (4) rating or (5) movie_id parameter to themes/flixer/ajax/update_rating.php; or the (6) id parameter to themes/flixer/ajax/set_player_source.php.

    Published: 12 Jan 2018
    6.1
    Medium

    CVE-2017-18014

    Last Modified: 21 Nov 2024

    An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a persistent XSS vulnerability found in the WAF log page (Control Center -> Log Viewer -> in the filter option "Web Server Protection") in the webadmin interface, and execute any action available to the webadmin of the firewall (e.g., creating a new user, enabling SSH, or adding an SSH authorized key). The WAF log page will execute the "User-Agent" parameter in the HTTP POST request.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2018-5262

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account.

    Published: 12 Jan 2018
    7.8
    High

    CVE-2017-0869

    Last Modified: 21 Nov 2024

    NVIDIA driver contains an integer overflow vulnerability which could cause a use after free and possibly lead to an elevation of privilege enabling code execution as a privileged process. This issue is rated as high. Version: N/A. Android ID: A-37776156. References: N-CVE-2017-0869.

    Published: 12 Jan 2018
    6.1
    Medium

    CVE-2017-14594

    Last Modified: 21 Nov 2024

    The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.

    Published: 12 Jan 2018
    4.3
    Medium

    CVE-2017-16862

    Last Modified: 21 Nov 2024

    The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability.

    Published: 12 Jan 2018
    6.1
    Medium

    CVE-2017-16864

    Last Modified: 21 Nov 2024

    The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter.

    Published: 12 Jan 2018