CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2011-2684

    Last Modified: 20 Apr 2025

    foo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged in Debian squeeze create temporary files insecurely, which allows local users to write over arbitrary files via a symlink attack on /tmp/foo2zjs.

    Published: 23 Oct 2017
    8.8
    High

    CVE-2011-4334

    Last Modified: 20 Apr 2025

    edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the userfile parameter.

    Published: 23 Oct 2017
    8.8
    High

    CVE-2017-13772

    Last Modified: 20 Apr 2025

    Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.

    Published: 23 Oct 2017
    6.1
    Medium

    CVE-2012-4567

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) inc/inc.ClassUI.php or (2) out/out.DocumentNotify.php.

    Published: 23 Oct 2017
    8.8
    High

    CVE-2012-4568

    Last Modified: 20 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 23 Oct 2017
    6.1
    Medium

    CVE-2012-4569

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in out/out.UsrMgr.php in LetoDMS (formerly MyDMS) before 3.3.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Oct 2017
    9.8
    Critical

    CVE-2012-4570

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Oct 2017
    8.1
    High

    CVE-2013-7377

    Last Modified: 20 Apr 2025

    The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.

    Published: 23 Oct 2017
    6.1
    Medium

    CVE-2011-4333

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) from parameter to index.php or the (2) page_no parameter to recentchanges.php.

    Published: 23 Oct 2017
    7.5
    High

    CVE-2014-3744

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.

    Published: 23 Oct 2017
    5.4
    Medium

    CVE-2015-5379

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inject arbitrary web script or HTML via an email attachment.

    Published: 23 Oct 2017
    7.2
    High

    CVE-2015-5533

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

    Published: 23 Oct 2017
    4.6
    Medium

    CVE-2015-6839

    Last Modified: 20 Apr 2025

    The parse function in MSA vot.Ar 3.1 does not check whether a candidate receives more than one vote, which allows physically proximate attackers to cast multiple votes for a candidate via a crafted RFID ballot tag.

    Published: 23 Oct 2017
    5.4
    Medium

    CVE-2017-15811

    Last Modified: 20 Apr 2025

    The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitable via wp-admin/admin-ajax.php.

    Published: 23 Oct 2017
    6.1
    Medium

    CVE-2017-15810

    Last Modified: 20 Apr 2025

    The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php.

    Published: 23 Oct 2017
    6.1
    Medium

    CVE-2017-15809

    Last Modified: 20 Apr 2025

    In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag.

    Published: 23 Oct 2017
    8.8
    High

    CVE-2017-15808

    Last Modified: 20 Apr 2025

    In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.

    Published: 23 Oct 2017
    6.1
    Medium

    CVE-2017-15812

    Last Modified: 20 Apr 2025

    The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel.

    Published: 23 Oct 2017
    8.8
    High

    CVE-2017-15378

    Last Modified: 20 Apr 2025

    SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI).

    Published: 23 Oct 2017
    9.8
    Critical

    CVE-2017-15379

    Last Modified: 20 Apr 2025

    An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.

    Published: 23 Oct 2017
    6.7
    Medium

    CVE-2017-14329

    Last Modified: 20 Apr 2025

    Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell.

    Published: 23 Oct 2017
    4.4
    Medium

    CVE-2017-14327

    Last Modified: 20 Apr 2025

    Extreme EXOS 16.x, 21.x, and 22.x allows administrators to read arbitrary files.

    Published: 23 Oct 2017
    7.5
    High

    CVE-2017-14328

    Last Modified: 20 Apr 2025

    Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot.

    Published: 23 Oct 2017
    6.7
    Medium

    CVE-2017-14331

    Last Modified: 20 Apr 2025

    Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell.

    Published: 23 Oct 2017
    8.1
    High

    CVE-2017-14332

    Last Modified: 20 Apr 2025

    Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values.

    Published: 23 Oct 2017
    7.5
    High

    CVE-2017-15377

    Last Modified: 20 Apr 2025

    In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic with a certain signature, because of DetectEngineContentInspection in detect-engine-content-inspection.c. The search engine doesn't stop when it should after no match is found; instead, it stops only upon reaching inspection-recursion-limit (3000 by default).

    Published: 23 Oct 2017
    9.8
    Critical

    CVE-2017-15381

    Last Modified: 20 Apr 2025

    SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).

    Published: 23 Oct 2017
    7.8
    High

    CVE-2017-15567

    Last Modified: 20 Apr 2025

    The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via unspecified vectors. NOTE: the vendor disputes this because there is no command shell in the product or in the associated SDK

    Published: 23 Oct 2017
    6.1
    Medium

    CVE-2017-15687

    Last Modified: 20 Apr 2025

    DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.

    Published: 23 Oct 2017
    7.5
    High

    CVE-2017-15805

    Last Modified: 20 Apr 2025

    Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.

    Published: 23 Oct 2017
    6.1
    Medium

    CVE-2017-15380

    Last Modified: 20 Apr 2025

    XSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the requester's registration area) via the nome parameter.

    Published: 23 Oct 2017
    6.7
    Medium

    CVE-2017-14330

    Last Modified: 20 Apr 2025

    Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.

    Published: 23 Oct 2017
    9.8
    Critical

    CVE-2017-15580

    Last Modified: 20 Apr 2025

    osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.

    Published: 23 Oct 2017
    9.8
    Critical

    CVE-2017-12796

    Last Modified: 20 Apr 2025

    The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users when deserializing XML input into ReportSchema objects. The result is that remote unauthenticated users are able to execute operating system commands by crafting malicious XML payloads, as demonstrated by a single admin/reports/reportSchemaXml.form request.

    Published: 23 Oct 2017
    3.3
    Low

    CVE-2017-7148

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Location Framework" component. It allows attackers to obtain sensitive location information via a crafted app that reads the location variable.

    Published: 23 Oct 2017
    7.5
    High

    CVE-2017-7080

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "Security" component. It allows remote attackers to bypass intended certificate-trust restrictions via a revoked X.509 certificate.

    Published: 23 Oct 2017
    6.5
    Medium

    CVE-2017-7085

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar.

    Published: 23 Oct 2017
    5.3
    Medium

    CVE-2017-7145

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Time" component. The "Setting Time Zone" feature mishandles the possibility of using location data.

    Published: 23 Oct 2017
    7.8
    High

    CVE-2017-7149

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "StorageKit" component. It allows attackers to discover passwords for APFS encrypted volumes by reading Disk Utility hints, because the stored hint value was accidentally set to the password itself, not the entered hint value.

    Published: 23 Oct 2017
    5.5
    Medium

    CVE-2017-7150

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13 Supplemental Update is affected. The issue involves the "Security" component. It allows attackers to bypass the keychain access prompt, and consequently extract passwords, via a synthetic click.

    Published: 23 Oct 2017
    3.7
    Low

    CVE-2017-7084

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Application Firewall" component. It allows remote attackers to bypass intended settings in opportunistic circumstances by leveraging incorrect handling of a denied setting after an upgrade.

    Published: 23 Oct 2017
    7.5
    High

    CVE-2017-7086

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the "libc" component. It allows remote attackers to cause a denial of service (resource consumption) via a crafted string that is mishandled by the glob function.

    Published: 23 Oct 2017
    5.9
    Medium

    CVE-2017-7088

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Exchange ActiveSync" component. It allows remote attackers to erase a device in opportunistic circumstances by hijacking a cleartext AutoDiscover V1 session during the setup of an Exchange account.

    Published: 23 Oct 2017
    8.8
    High

    CVE-2017-7091

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 23 Oct 2017
    5.5
    Medium

    CVE-2017-7097

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Mail MessageUI" component. It allows attackers to cause a denial of service (memory corruption) via a crafted image.

    Published: 23 Oct 2017
    8.8
    High

    CVE-2017-7104

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 23 Oct 2017
    8.8
    High

    CVE-2017-7117

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 23 Oct 2017
    9.8
    Critical

    CVE-2017-7124

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 23 Oct 2017
    5.5
    Medium

    CVE-2017-7131

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Bluetooth" component. It allows attackers to obtain sensitive Contact card information via a crafted app.

    Published: 23 Oct 2017
    7.8
    High

    CVE-2017-7134

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Mach-O file.

    Published: 23 Oct 2017