CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2012-6696

    Last Modified: 20 Apr 2025

    inspircd in Debian before 2.0.7 does not properly handle unsigned integers. NOTE: This vulnerability exists because of an incomplete fix to CVE-2012-1836.

    Published: 25 Sept 2017
    5.9
    Medium

    CVE-2011-4667

    Last Modified: 20 Apr 2025

    The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco MDS 9222i Multiservice Modular Switch, Cisco MDS 9000 18/4-Port Multiservice Module, and Cisco MDS 9000 Storage Services Node module before 5.2(6), and Cisco IOS in Cisco VPN Services Port Adaptor for Catalyst 6500 12.2(33)SXI, and 12.2(33)SXJ when IP Security (aka IPSec) is used, allows remote attackers to obtain unencrypted packets from encrypted sessions.

    Published: 25 Sept 2017
    6.5
    Medium

    CVE-2017-14731

    Last Modified: 20 Apr 2025

    ofx_proc_file in ofx_preproc.cpp in LibOFX 0.9.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file, as demonstrated by an ofxdump call.

    Published: 25 Sept 2017
    8.1
    High

    CVE-2015-5263

    Last Modified: 20 Apr 2025

    pulp-consumer-client 2.4.0 through 2.6.3 does not check the server's TLS certificate signatures when retrieving the server's public key upon registration.

    Published: 25 Sept 2017
    6.8
    Medium

    CVE-2015-6592

    Last Modified: 20 Apr 2025

    Huawei UAP2105 before V300R012C00SPC160(BootRom) does not require authentication to the serial port or the VxWorks shell.

    Published: 25 Sept 2017
    8.8
    High

    CVE-2015-7293

    Last Modified: 20 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.

    Published: 25 Sept 2017
    4.6
    Medium

    CVE-2015-7846

    Last Modified: 20 Apr 2025

    Huawei S7700, S9700, S9300 before V200R07C00SPC500, and AR200, AR1200, AR2200, AR3200 before V200R005C20SPC200 allows attackers with physical access to the CF card to obtain sensitive information.

    Published: 25 Sept 2017
    5.9
    Medium

    CVE-2015-8251

    Last Modified: 20 Apr 2025

    OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phone IP 35G Eco SIP V3, OpenStage 60 and OpenScape Desk Phone IP 55G HFA V3, OpenStage 15, 20E, 20, and 40 and OpenScape Desk Phone IP 35G HFA V3, and OpenScape Desk Phone IP 35G Eco HFA V3 use non-unique X.509 certificates and SSH host keys.

    Published: 25 Sept 2017
    5.9
    Medium

    CVE-2015-5666

    Last Modified: 20 Apr 2025

    ANA App for Android 3.1.1 and earlier, and ANA App for iOS 3.3.6 and earlier does not verify SSL certificates.

    Published: 25 Sept 2017
    7.8
    High

    CVE-2015-5704

    Last Modified: 20 Apr 2025

    scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.

    Published: 25 Sept 2017
    5.9
    Medium

    CVE-2015-7785

    Last Modified: 20 Apr 2025

    GANMA! App for iOS does not verify SSL certificates.

    Published: 25 Sept 2017
    5.4
    Medium

    CVE-2015-8375

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.

    Published: 25 Sept 2017
    7
    High

    CVE-2016-5868

    Last Modified: 20 Apr 2025

    drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arbitrary code via a crafted application compromising a privileged process.

    Published: 25 Sept 2017
    6.5
    Medium

    CVE-2017-14733

    Last Modified: 20 Apr 2025

    ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

    Published: 25 Sept 2017
    8.8
    High

    CVE-2017-14734

    Last Modified: 20 Apr 2025

    The build_msps function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted BPG file, related to hevc_decode_init1.

    Published: 25 Sept 2017
    6.1
    Medium

    CVE-2017-14735

    Last Modified: 20 Apr 2025

    OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL.

    Published: 25 Sept 2017
    7.5
    High

    CVE-2014-0997

    Last Modified: 20 Apr 2025

    WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android 4.1.2 as used in the Motorola RAZR HD, and potentially other unspecified Android releases before 5.0.1 and 5.0.2 does not properly handle exceptions, which allows remote attackers to cause a denial of service (reboot) via a crafted 802.11 probe response frame.

    Published: 25 Sept 2017
    7.8
    High

    CVE-2014-8156

    Last Modified: 20 Apr 2025

    The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-4, and fso-usaged 0.12.0-2 as packaged in Debian, the upstream cornucopia.git (fsoaudiod, fsodatad, fsodeviced, fsogsmd, fsonetworkd, fsotdld, fsousaged) git master on 2015-01-19, the upstream framework.git 0.10.1 and git master on 2015-01-19, phonefsod 0.1+git20121018-1 as packaged in Debian, Ubuntu and potentially other packages, and potentially other fso modules do not properly filter D-Bus message paths, which might allow local users to cause a denial of service (dbus-daemon memory consumption), or execute arbitrary code as root by sending a crafted D-Bus message to any D-Bus system service.

    Published: 25 Sept 2017
    5.5
    Medium

    CVE-2017-9959

    Last Modified: 20 Apr 2025

    A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system accepts reboot in session from unauthenticated users, supporting a denial of service condition.

    Published: 25 Sept 2017
    5.3
    Medium

    CVE-2014-8889

    Last Modified: 20 Apr 2025

    Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.

    Published: 25 Sept 2017
    9.8
    Critical

    CVE-2015-8707

    Last Modified: 20 Apr 2025

    Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via a crafted external service with access to the referrer field.

    Published: 25 Sept 2017
    6.5
    Medium

    CVE-2017-7971

    Last Modified: 20 Apr 2025

    A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the use of outdated cipher suites and improper verification of peer SSL Certificate.

    Published: 25 Sept 2017
    5.5
    Medium

    CVE-2017-7972

    Last Modified: 20 Apr 2025

    A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to escape out of remote PowerSCADA Anywhere applications and launch other processes.

    Published: 25 Sept 2017
    9.8
    Critical

    CVE-2017-7973

    Last Modified: 20 Apr 2025

    A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can use calls to various paths allowing performance of arbitrary SQL commands against the underlying database.

    Published: 25 Sept 2017
    9.8
    Critical

    CVE-2017-7974

    Last Modified: 20 Apr 2025

    A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an unauthenticated user can execute arbitrary code and exfiltrate files.

    Published: 25 Sept 2017
    7.3
    High

    CVE-2017-9956

    Last Modified: 20 Apr 2025

    An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system contains a hard-coded valid session. An attacker can use that session ID as part of the HTTP cookie of a web request, resulting in authentication bypass

    Published: 25 Sept 2017
    9.8
    Critical

    CVE-2017-9957

    Last Modified: 20 Apr 2025

    A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-privilege credentials.

    Published: 25 Sept 2017
    7.8
    High

    CVE-2017-9958

    Last Modified: 20 Apr 2025

    An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handling of the system configuration can allow an attacker to execute arbitrary code under the context of root.

    Published: 25 Sept 2017
    7.8
    High

    CVE-2017-9961

    Last Modified: 20 Apr 2025

    A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code installation requires an access to the computer. By placing a specific DLL/OCX file, an attacker is able to force the process to load arbitrary DLL and execute arbitrary code in the context of the process.

    Published: 25 Sept 2017
    7.5
    High

    CVE-2017-9962

    Last Modified: 20 Apr 2025

    Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affected include ViewX and the Server Icon.

    Published: 25 Sept 2017
    8.8
    High

    CVE-2017-7969

    Last Modified: 20 Apr 2025

    A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack.

    Published: 25 Sept 2017
    6.5
    Medium

    CVE-2017-7970

    Last Modified: 20 Apr 2025

    A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components.

    Published: 25 Sept 2017
    5.3
    Medium

    CVE-2017-9960

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.

    Published: 25 Sept 2017
    5.5
    Medium

    CVE-2010-3049

    Last Modified: 20 Apr 2025

    Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot).

    Published: 25 Sept 2017
    6.5
    Medium

    CVE-2010-3050

    Last Modified: 20 Apr 2025

    Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot).

    Published: 25 Sept 2017
    7.8
    High

    CVE-2017-14730

    Last Modified: 20 Apr 2025

    The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.

    Published: 25 Sept 2017
    9.8
    Critical

    CVE-2015-4667

    Last Modified: 20 Apr 2025

    Multiple hardcoded credentials in Xsuite 2.x.

    Published: 25 Sept 2017
    6.1
    Medium

    CVE-2015-4668

    Last Modified: 20 Apr 2025

    Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.

    Published: 25 Sept 2017
    7.8
    High

    CVE-2015-4669

    Last Modified: 20 Apr 2025

    The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.

    Published: 25 Sept 2017
    10
    Critical

    CVE-2017-12905

    Last Modified: 20 Apr 2025

    Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.

    Published: 25 Sept 2017
    9.8
    Critical

    CVE-2017-14125

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "id" parameter in an add_edit_theme task in the wpdevart_gallery_themes page to wp-admin/admin.php.

    Published: 25 Sept 2017
    6.5
    Medium

    CVE-2017-1235

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ 8.0 could allow an authenticated user to cause a premature termination of a client application thread which could potentially cause denial of service. IBM X-Force ID: 123914.

    Published: 25 Sept 2017
    6.1
    Medium

    CVE-2017-1551

    Last Modified: 20 Apr 2025

    IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 131291.

    Published: 25 Sept 2017
    5.4
    Medium

    CVE-2017-1424

    Last Modified: 20 Apr 2025

    IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127477.

    Published: 25 Sept 2017
    2.5
    Low

    CVE-2017-1346

    Last Modified: 20 Apr 2025

    IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461.

    Published: 25 Sept 2017
    7.8
    High

    CVE-2017-1362

    Last Modified: 20 Apr 2025

    IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 126801.

    Published: 25 Sept 2017
    4.3
    Medium

    CVE-2017-1555

    Last Modified: 20 Apr 2025

    IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed to the application plan. IBM X-Force ID: 131545.

    Published: 25 Sept 2017
    6.1
    Medium

    CVE-2017-9551

    Last Modified: 20 Apr 2025

    Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr_registration table. The values are then emailed to the the user and administrator and if accepted become part of the new user's account.

    Published: 25 Sept 2017
    5.4
    Medium

    CVE-2017-14506

    Last Modified: 20 Apr 2025

    geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file.

    Published: 25 Sept 2017
    8.8
    High

    CVE-2017-14683

    Last Modified: 20 Apr 2025

    geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload.

    Published: 25 Sept 2017