CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2017-6796

    Last Modified: 20 Apr 2025

    A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the platform usb modem command in the CLI of the affected software. An attacker could exploit this vulnerability by modifying the platform usb modem command in the CLI of an affected device. A successful exploit could allow the attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. Cisco Bug IDs: CSCve48949.

    Published: 7 Sept 2017
    7.5
    High

    CVE-2017-6627

    Last Modified: 22 Apr 2026

    A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacker to cause UDP packets to be held in the input interfaces queue, resulting in a DoS condition. The input interface queue will stop holding UDP packets when it receives 250 packets. Cisco Bug IDs: CSCup10024, CSCva55744, CSCva95506.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2017-12212

    Last Modified: 20 Apr 2025

    A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via the HTTP GET and HTTP POST methods. An attacker who can convince a user to follow an attacker-supplied link could execute arbitrary script or HTML code in the user's browser in the context of an affected site. Known Affected Releases 10.5(2). Cisco Bug IDs: CSCvf25345.

    Published: 7 Sept 2017
    5.3
    Medium

    CVE-2017-12217

    Last Modified: 20 Apr 2025

    A vulnerability in the General Packet Radio Service (GPRS) Tunneling Protocol ingress packet handler of Cisco ASR 5500 System Architecture Evolution (SAE) Gateways could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation of GPRS Tunneling Protocol packet headers. An attacker could exploit this vulnerability by sending a malformed GPRS Tunneling Protocol packet to an affected device. A successful exploit could allow the attacker to cause the GTPUMGR process on an affected device to restart unexpectedly, resulting in a partial DoS condition. If the GTPUMGR process restarts, there could be a brief impact on traffic passing through the device. Cisco Bug IDs: CSCve07119.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2017-12220

    Last Modified: 20 Apr 2025

    A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvc50771.

    Published: 7 Sept 2017
    5.4
    Medium

    CVE-2017-12221

    Last Modified: 20 Apr 2025

    A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the affected software. Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code in the context of the affected system. Cisco Bug IDs: CSCvc38983.

    Published: 7 Sept 2017
    6.4
    Medium

    CVE-2017-12223

    Last Modified: 20 Apr 2025

    A vulnerability in the ROM Monitor (ROMMON) code of Cisco IR800 Integrated Services Router Software could allow an unauthenticated, local attacker to boot an unsigned Hypervisor on an affected device and compromise the integrity of the system. The vulnerability is due to insufficient sanitization of user input. An attacker who can access an affected router via the console could exploit this vulnerability by entering ROMMON mode and modifying ROMMON variables. A successful exploit could allow the attacker to execute arbitrary code and install a malicious version of Hypervisor firmware on an affected device. Cisco Bug IDs: CSCvb44027.

    Published: 7 Sept 2017
    5.4
    Medium

    CVE-2017-12227

    Last Modified: 20 Apr 2025

    A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that bypass protection filters. An attacker could exploit this vulnerability by sending crafted URLs that include SQL statements. An exploit could allow the attacker to view or modify entries in some database tables, affecting the integrity of the data. Cisco Bug IDs: CSCvb58973.

    Published: 7 Sept 2017
    7.5
    High

    CVE-2017-6631

    Last Modified: 20 Apr 2025

    A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manufactured by Cisco for Yes could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the firmware of an affected device fails to handle certain XML values that are passed to the HTTP RPC service listening on the local subnet of the device. An attacker could exploit this vulnerability by submitting a malformed request to an affected device. A successful attack could cause the affected device to restart, resulting in a DoS condition. Yes has updated the affected devices with firmware that addresses this vulnerability. Customers are not required to take action. Vulnerable Products: This vulnerability affects YesMaxTotal, YesMax HD, and YesQuattro STB devices. Cisco Bug IDs: CSCvd08812.

    Published: 7 Sept 2017
    7.5
    High

    CVE-2017-6780

    Last Modified: 20 Apr 2025

    A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to cause the system to consume additional memory, eventually forcing the device to restart, aka Memory Exhaustion. The vulnerability is due to insufficient rate-limiting protection. An attacker could exploit this vulnerability by sending a high rate of TCP packets to a specific group of open listening ports on a targeted device. An exploit could allow the attacker to cause the system to consume additional memory. If enough available memory is consumed, the system will restart, creating a temporary denial of service (DoS) condition. The DoS condition will end after the device has finished the restart process. This vulnerability affects the following Cisco products: Connected Grid Network Management System, if running a software release prior to IoT-FND Release 4.0; IoT Field Network Director, if running a software release prior to IoT-FND Release 4.0. Cisco Bug IDs: CSCvc77164.

    Published: 7 Sept 2017
    9.8
    Critical

    CVE-2015-3991

    Last Modified: 20 Apr 2025

    strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.

    Published: 7 Sept 2017
    8.8
    High

    CVE-2015-4619

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Spina before commit bfe44f289e336f80b6593032679300c493735e75.

    Published: 7 Sept 2017
    9.8
    Critical

    CVE-2015-4629

    Last Modified: 20 Apr 2025

    Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN/PUK authentication, and perform other unspecified actions.

    Published: 7 Sept 2017
    8.8
    High

    CVE-2015-4697

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.

    Published: 7 Sept 2017
    9.8
    Critical

    CVE-2015-5052

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Sefrengo before 1.6.5 beta2.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2015-5060

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.

    Published: 7 Sept 2017
    8.8
    High

    CVE-2014-9565

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earlier.

    Published: 7 Sept 2017
    8.8
    High

    CVE-2015-4724

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Concrete5 5.7.3.1.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2015-3169

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in askbot 0.7.51-4.el6.noarch.

    Published: 7 Sept 2017
    7
    High

    CVE-2015-3222

    Last Modified: 20 Apr 2025

    syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.

    Published: 7 Sept 2017
    9.8
    Critical

    CVE-2015-3313

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in WordPress Community Events plugin before 1.4.

    Published: 7 Sept 2017
    8.1
    High

    CVE-2015-3314

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.

    Published: 7 Sept 2017
    7.5
    High

    CVE-2015-4085

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.

    Published: 7 Sept 2017
    9.8
    Critical

    CVE-2015-4627

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Pragyan CMS 3.0.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2015-4721

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.

    Published: 7 Sept 2017
    5.4
    Medium

    CVE-2015-7672

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).

    Published: 7 Sept 2017
    5.3
    Medium

    CVE-2015-8079

    Last Modified: 20 Apr 2025

    qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2017-14193

    Last Modified: 20 Apr 2025

    The oauth function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Internet Explorer.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2017-14194

    Last Modified: 20 Apr 2025

    The out function in controllers/member/Login.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Internet Explorer.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2017-14195

    Last Modified: 20 Apr 2025

    The call_msg function in controllers/Form.php in dayrui FineCms 5.0.11 might have XSS related to the Referer HTTP header with Internet Explorer.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2017-14192

    Last Modified: 20 Apr 2025

    The checktitle function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the module field.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2017-1189

    Last Modified: 20 Apr 2025

    IBM WebSphere Portal and Web Content Manager 6.1, 7.0, and 8.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123558.

    Published: 7 Sept 2017
    7.5
    High

    CVE-2013-7428

    Last Modified: 20 Apr 2025

    The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to cause a denial of service via the url parameter to plugin_googlemap2_proxy.php.

    Published: 7 Sept 2017
    5.4
    Medium

    CVE-2017-1098

    Last Modified: 20 Apr 2025

    IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120658.

    Published: 7 Sept 2017
    7.8
    High

    CVE-2017-14181

    Last Modified: 20 Apr 2025

    DeleteBitBuffer in libbitbuf/bitbuffer.c in mp4tools aacplusenc 0.17.5 allows remote attackers to cause a denial of service (invalid memory write, SEGV on unknown address 0x000000000030, and application crash) or possibly have unspecified other impact via a crafted .wav file, aka a NULL pointer dereference.

    Published: 7 Sept 2017
    5.4
    Medium

    CVE-2017-1502

    Last Modified: 20 Apr 2025

    IBM Content Navigator & CMIS 2.0.3, 3.0.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129577.

    Published: 7 Sept 2017
    7.8
    High

    CVE-2015-1590

    Last Modified: 20 Apr 2025

    The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.

    Published: 7 Sept 2017
    5.5
    Medium

    CVE-2017-12911

    Last Modified: 20 Apr 2025

    The "apetag.c" file in MP3Gain 1.5.2.r2 has a vulnerability which results in a stack memory corruption when opening a crafted MP3 file.

    Published: 7 Sept 2017
    5.5
    Medium

    CVE-2017-12912

    Last Modified: 20 Apr 2025

    The "mpglibDBL/layer3.c" file in MP3Gain 1.5.2.r2 has a vulnerability which results in a read access violation when opening a crafted MP3 file.

    Published: 7 Sept 2017
    9.8
    Critical

    CVE-2017-14147

    Last Modified: 20 Apr 2025

    An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it. Due to improper authentication on this page, the software accepts the request hence allowing attacker to reset the router to its default configurations which later could allow attacker to login to router by using default username/password.

    Published: 7 Sept 2017
    7.8
    High

    CVE-2017-9779

    Last Modified: 20 Apr 2025

    OCaml compiler allows attackers to have unspecified impact via unknown vectors, a similar issue to CVE-2017-9772 "but with much less impact."

    Published: 7 Sept 2017
    9.8
    Critical

    CVE-2017-9834

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the watupro_questions parameter in a watupro_submit action to wp-admin/admin-ajax.php.

    Published: 7 Sept 2017
    7.5
    High

    CVE-2015-3250

    Last Modified: 20 Apr 2025

    Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.

    Published: 7 Sept 2017
    9.8
    Critical

    CVE-2017-9458

    Last Modified: 20 Apr 2025

    XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to obtain sensitive information, cause a denial of service, or conduct server-side request forgery (SSRF) attacks via unspecified vectors.

    Published: 7 Sept 2017
    9.8
    Critical

    CVE-2015-3442

    Last Modified: 20 Apr 2025

    Soreco Xpert.Line 3.0 allows local users to spoof users and consequently gain privileges by intercepting a Windows API call.

    Published: 7 Sept 2017
    8.8
    High

    CVE-2016-0732

    Last Modified: 20 Apr 2025

    The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.

    Published: 7 Sept 2017
    9.8
    Critical

    CVE-2016-10405

    Last Modified: 20 Apr 2025

    Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 7 Sept 2017
    8.8
    High

    CVE-2017-12838

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in NexusPHP 1.5 allows remote attackers to hijack the authentication of users for requests that (1) send manas via a request to mybonus.php or (2) add administrators via unspecified vectors.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2017-12906

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in NexusPHP allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) cheaters.php or (2) confirm_resend.php.

    Published: 7 Sept 2017
    8.8
    High

    CVE-2017-13713

    Last Modified: 20 Apr 2025

    T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user parameter to cgi-bin/webupg.

    Published: 7 Sept 2017