CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2015-2144

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) project name parameter to project.php; the (2) use_js parameter to user.php; the (3) use_js parameter to group.php; the (4) Description parameter to status.php; the (5) Description parameter to severity.php; the (6) Regex parameter to os.php; or the (7) Name parameter to database.php.

    Published: 6 Oct 2017
    5.4
    Medium

    CVE-2014-8957

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML via the Tasks parameter.

    Published: 6 Oct 2017
    7.5
    High

    CVE-2015-1429

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Cybele Software Thinfinity Remote Desktop Workstation 3.0.0.3 32-bit and 64-bit allows remote attackers to download arbitrary files via a .. (dot dot) in an unspecified parameter.

    Published: 6 Oct 2017
    8.8
    High

    CVE-2015-2143

    Last Modified: 20 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentication of users for requests that cause an unspecified impact via unknown parameters.

    Published: 6 Oct 2017
    4.8
    Medium

    CVE-2015-2145

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 6 Oct 2017
    9.8
    Critical

    CVE-2015-2146

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to project.php, the (2) group_id parameter to group.php, the (3) status_id parameter to status.php, the (4) resolution_id parameter to resolution.php, the (5) severity_id parameter to severity.php, the (6) priority_id parameter to priority.php, the (7) os_id parameter to os.php, or the (8) site_id parameter to site.php.

    Published: 6 Oct 2017
    9.8
    Critical

    CVE-2015-2147

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.

    Published: 6 Oct 2017
    6.5
    Medium

    CVE-2017-15084

    Last Modified: 20 Apr 2025

    The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.

    Published: 6 Oct 2017
    9.8
    Critical

    CVE-2017-13069

    Last Modified: 20 Apr 2025

    QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to run arbitrary commands on the NAS.

    Published: 6 Oct 2017
    7.5
    High

    CVE-2017-15079

    Last Modified: 20 Apr 2025

    The Smush Image Compression and Optimization plugin before 2.7.6 for WordPress allows directory traversal.

    Published: 6 Oct 2017
    7.5
    High

    CVE-2017-13068

    Last Modified: 20 Apr 2025

    QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15065

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15068

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15069

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15067

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    7.5
    High

    CVE-2017-1002153

    Last Modified: 20 Apr 2025

    Koji 1.13.0 does not properly validate SCM paths, allowing an attacker to work around blacklisted paths for build submission.

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15072

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15073

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15074

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15075

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15076

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15077

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15078

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15070

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15071

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15064

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    7.5
    High

    CVE-2017-9272

    Last Modified: 20 Apr 2025

    The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to a denial of service attack.

    Published: 6 Oct 2017
    5.3
    Medium

    CVE-2017-9273

    Last Modified: 20 Apr 2025

    The Bi-directional driver in IDM 4.5 before 4.0.3.0 could be susceptible to unauthorized log configuration changes.

    Published: 6 Oct 2017
    Unknown

    CVE-2017-15066

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none

    Published: 6 Oct 2017
    5.9
    Medium

    CVE-2014-2903

    Last Modified: 20 Apr 2025

    CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.

    Published: 6 Oct 2017
    5.5
    Medium

    CVE-2015-1206

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of service (unpaged memory write and process crash) via a crafted MP4 file.

    Published: 6 Oct 2017
    7.5
    High

    CVE-2015-2297

    Last Modified: 20 Apr 2025

    nanohttp in libcsoap allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Authorization header.

    Published: 6 Oct 2017
    6.1
    Medium

    CVE-2014-8492

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter.

    Published: 6 Oct 2017
    6.1
    Medium

    CVE-2014-8758

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.

    Published: 6 Oct 2017
    6.1
    Medium

    CVE-2014-7240

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value parameter in a master_response action to wp-admin/admin-ajax.php.

    Published: 6 Oct 2017
    7.8
    High

    CVE-2017-15056

    Last Modified: 20 Apr 2025

    p_lx_elf.cpp in UPX 3.94 mishandles ELF headers, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by an Invalid Pointer Read in PackLinuxElf64::unpack().

    Published: 6 Oct 2017
    8.8
    High

    CVE-2017-15063

    Last Modified: 20 Apr 2025

    There are CSRF vulnerabilities in Subrion CMS 4.1.x through 4.1.5, and before 4.2.0, because of a logic error. Although there is functionality to detect CSRF, it is called too late in the ia.core.php code, allowing (for example) an attack against the query parameter to panel/database.

    Published: 6 Oct 2017
    7.8
    High

    CVE-2017-12730

    Last Modified: 20 Apr 2025

    An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior. Application services utilize unquoted search path elements, which could allow an attacker to execute arbitrary code with elevated privileges.

    Published: 6 Oct 2017
    8.8
    High

    CVE-2017-15365

    Last Modified: 21 Nov 2024

    sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.

    Published: 6 Oct 2017
    8.8
    High

    CVE-2017-13996

    Last Modified: 20 Apr 2025

    A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative users should not have access to, which could allow an attacker to create or modify files or execute arbitrary code.

    Published: 5 Oct 2017
    6.8
    Medium

    CVE-2017-12732

    Last Modified: 20 Apr 2025

    A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrite that could lead to an arbitrary remote code execution.

    Published: 5 Oct 2017
    8.1
    High

    CVE-2017-13992

    Last Modified: 20 Apr 2025

    An Insufficient Entropy issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not utilize sufficiently random number generation for the web interface authentication mechanism, which could allow remote code execution.

    Published: 5 Oct 2017
    6.1
    Medium

    CVE-2017-13994

    Last Modified: 20 Apr 2025

    A Cross-site Scripting issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web interface lacks proper web request validation, which could allow XSS attacks to occur if an authenticated user of the web interface is tricked into clicking a malicious link.

    Published: 5 Oct 2017
    7.5
    High

    CVE-2017-13998

    Last Modified: 20 Apr 2025

    An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protect sensitive information from unauthorized access.

    Published: 5 Oct 2017
    7.8
    High

    CVE-2017-2880

    Last Modified: 20 Apr 2025

    An memory corruption vulnerability exists in the .GIF parsing functionality of Computerinsel Photoline 20.02. A specially crafted .GIF file can cause a vulnerability resulting in potential code execution. An attacker can send specific .GIF file to trigger this vulnerability.

    Published: 5 Oct 2017
    8.8
    High

    CVE-2017-12106

    Last Modified: 20 Apr 2025

    A memory corruption vulnerability exists in the .TGA parsing functionality of Computerinsel Photoline 20.02. A specially crafted .TGA file can cause an out of bounds write resulting in potential code execution. An attacker can send a specific .TGA file to trigger this vulnerability.

    Published: 5 Oct 2017
    7.8
    High

    CVE-2017-2920

    Last Modified: 20 Apr 2025

    An memory corruption vulnerability exists in the .SVG parsing functionality of Computerinsel Photoline 20.02. A specially crafted .SVG file can cause a vulnerability resulting in memory corruption, which can potentially lead to arbitrary code execution. An attacker can send a specific .SVG file to trigger this vulnerability.

    Published: 5 Oct 2017
    5.5
    Medium

    CVE-2017-1301

    Last Modified: 20 Apr 2025

    IBM Spectrum Protect 7.1 and 8.1 could allow a local attacker to launch a symlink attack. IBM Spectrum Protect Backup-archive Client creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various files on the system, which could allow the attacker to overwrite arbitrary files on the system with elevated privileges. IBM X-Force ID: 125163.

    Published: 5 Oct 2017
    7.8
    High

    CVE-2017-1378

    Last Modified: 20 Apr 2025

    IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) disclosed unencrypted login credentials to Vmware vCenter in the application trace output which could be obtained by a local user. IBM X-Force ID: 126875.

    Published: 5 Oct 2017
    4.4
    Medium

    CVE-2017-1339

    Last Modified: 20 Apr 2025

    IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum protect client or administrator password which can result in information disclosure or a denial of service. IBM X-Force ID: 126247.

    Published: 5 Oct 2017