CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2017-13760

    Last Modified: 20 Apr 2025

    In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.

    Published: 29 Aug 2017
    5.5
    Medium

    CVE-2017-13756

    Last Modified: 20 Apr 2025

    In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.

    Published: 29 Aug 2017
    5.5
    Medium

    CVE-2017-13755

    Last Modified: 20 Apr 2025

    In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as demonstrated by fls.

    Published: 29 Aug 2017
    3.3
    Low

    CVE-2016-2978

    Last Modified: 20 Apr 2025

    IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2017-1195

    Last Modified: 20 Apr 2025

    IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 123670.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2017-1427

    Last Modified: 20 Apr 2025

    IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127579.

    Published: 29 Aug 2017
    5.4
    Medium

    CVE-2017-1485

    Last Modified: 20 Apr 2025

    IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128623.

    Published: 29 Aug 2017
    6.3
    Medium

    CVE-2016-2980

    Last Modified: 20 Apr 2025

    The Sametime WebPlayer 8.5.2 and 9.0 is vulnerable to a script injection where a malicious site can inject their own script by exploiting a vulnerability in the way that the WebPlayer works. IBM X-Force ID: 113993.

    Published: 29 Aug 2017
    4.3
    Medium

    CVE-2016-0358

    Last Modified: 20 Apr 2025

    IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928.

    Published: 29 Aug 2017
    5.3
    Medium

    CVE-2016-2964

    Last Modified: 20 Apr 2025

    IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the application. IBM X-Force ID: 113813.

    Published: 29 Aug 2017
    4.3
    Medium

    CVE-2016-2966

    Last Modified: 20 Apr 2025

    IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-Force ID: 113847.

    Published: 29 Aug 2017
    5.4
    Medium

    CVE-2016-2967

    Last Modified: 20 Apr 2025

    IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Sametime away message altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113848.

    Published: 29 Aug 2017
    3.3
    Low

    CVE-2016-2974

    Last Modified: 20 Apr 2025

    IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934.

    Published: 29 Aug 2017
    5.4
    Medium

    CVE-2016-2975

    Last Modified: 20 Apr 2025

    IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113935.

    Published: 29 Aug 2017
    4.3
    Medium

    CVE-2016-2976

    Last Modified: 20 Apr 2025

    IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by viewing the meeting report history. IBM X-Force ID: 113936.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2017-1428

    Last Modified: 20 Apr 2025

    IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 127583.

    Published: 29 Aug 2017
    5.4
    Medium

    CVE-2017-1535

    Last Modified: 20 Apr 2025

    IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130677.

    Published: 29 Aug 2017
    9.8
    Critical

    CVE-2013-7426

    Last Modified: 20 Apr 2025

    Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.

    Published: 29 Aug 2017
    5.3
    Medium

    CVE-2013-7431

    Last Modified: 20 Apr 2025

    Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2013-7432

    Last Modified: 20 Apr 2025

    The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2013-7433

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2017-3150

    Last Modified: 20 Apr 2025

    Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating use cookies that could be accessible to client-side script.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2017-3152

    Last Modified: 20 Apr 2025

    Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2017-3153

    Last Modified: 20 Apr 2025

    Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2014-9497

    Last Modified: 20 Apr 2025

    Buffer overflow in mpg123 before 1.18.0.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2016-8752

    Last Modified: 20 Apr 2025

    Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2017-3154

    Last Modified: 20 Apr 2025

    Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2017-3155

    Last Modified: 20 Apr 2025

    Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to cross frame scripting.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2017-3151

    Last Modified: 20 Apr 2025

    Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Stored Cross-Site Scripting in the edit-tag functionality.

    Published: 29 Aug 2017
    4.3
    Medium

    CVE-2016-2959

    Last Modified: 20 Apr 2025

    IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Force ID: 113804.

    Published: 29 Aug 2017
    4.3
    Medium

    CVE-2016-2969

    Last Modified: 20 Apr 2025

    IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM X-Force ID: 113850.

    Published: 29 Aug 2017
    4.3
    Medium

    CVE-2016-2977

    Last Modified: 20 Apr 2025

    IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID: 113937.

    Published: 29 Aug 2017
    5.4
    Medium

    CVE-2016-2979

    Last Modified: 20 Apr 2025

    IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113945.

    Published: 29 Aug 2017
    6.5
    Medium

    CVE-2016-0356

    Last Modified: 20 Apr 2025

    IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895.

    Published: 29 Aug 2017
    5.5
    Medium

    CVE-2016-0354

    Last Modified: 20 Apr 2025

    IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload a malicious file to a Sametime meeting room, that could be downloaded by unsuspecting users which could be executed with user privileges. IBM X-Force ID: 111893.

    Published: 29 Aug 2017
    6.5
    Medium

    CVE-2016-0355

    Last Modified: 20 Apr 2025

    IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111894.

    Published: 29 Aug 2017
    4.3
    Medium

    CVE-2016-10503

    Last Modified: 20 Apr 2025

    IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. IBM X-Force ID: 113803.

    Published: 29 Aug 2017
    6.5
    Medium

    CVE-2016-2965

    Last Modified: 20 Apr 2025

    IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM X-Force ID: 113846.

    Published: 29 Aug 2017
    5.3
    Medium

    CVE-2016-2971

    Last Modified: 20 Apr 2025

    IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. IBM X-Force ID: 113898.

    Published: 29 Aug 2017
    7.8
    High

    CVE-2016-2972

    Last Modified: 20 Apr 2025

    IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.

    Published: 29 Aug 2017
    5.4
    Medium

    CVE-2016-2973

    Last Modified: 20 Apr 2025

    IBM Sametime Media Services 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 113899.

    Published: 29 Aug 2017
    9.8
    Critical

    CVE-2017-12865

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" variable.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2015-7255

    Last Modified: 20 Apr 2025

    ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device.

    Published: 29 Aug 2017
    6.5
    Medium

    CVE-2017-12422

    Last Modified: 20 Apr 2025

    NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arbitrary objects via unspecified vectors.

    Published: 29 Aug 2017
    5.9
    Medium

    CVE-2017-12867

    Last Modified: 20 Apr 2025

    The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.

    Published: 29 Aug 2017
    6.5
    Medium

    CVE-2017-12875

    Last Modified: 20 Apr 2025

    The WritePixelCachePixels function in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (CPU consumption) via a crafted file.

    Published: 29 Aug 2017
    7.2
    High

    CVE-2015-3653

    Last Modified: 20 Apr 2025

    Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files within the underlying operating system and consequently cause a denial of service or gain privileges by leveraging incorrect permission checking.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2015-5209

    Last Modified: 20 Apr 2025

    Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2015-6588

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in login-fsp.html in MODX Revolution before 1.9.1 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.

    Published: 29 Aug 2017
    9.8
    Critical

    CVE-2015-8299

    Last Modified: 20 Apr 2025

    Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute arbitrary code via a crafted KNXnet/IP UDP packet.

    Published: 29 Aug 2017