CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-10843

    Last Modified: 20 Apr 2025

    baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form.

    Published: 28 Aug 2017
    8.8
    High

    CVE-2017-10844

    Last Modified: 20 Apr 2025

    baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-2242

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Flets Setsuzoku Tool for Windows all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Aug 2017
    5.4
    Medium

    CVE-2017-2256

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2017-2257

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via mail function.

    Published: 28 Aug 2017
    4.3
    Medium

    CVE-2017-2258

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-3746

    Last Modified: 20 Apr 2025

    ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege escalation vulnerability that could allow a local user to execute arbitrary code with administrative or system level privileges.

    Published: 28 Aug 2017
    9.8
    Critical

    CVE-2017-10832

    Last Modified: 20 Apr 2025

    "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 28 Aug 2017
    8.8
    High

    CVE-2017-10835

    Last Modified: 20 Apr 2025

    "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vectors.

    Published: 28 Aug 2017
    4.9
    Medium

    CVE-2017-10841

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-1110

    Last Modified: 20 Apr 2025

    IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the incidents of a higher privileged user. IBM X-Force ID: 120915.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-3757

    Last Modified: 20 Apr 2025

    An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on some Lenovo brand notebooks (not ThinkPads). This could allow an attacker with local privileges to execute code with administrative privileges.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12925

    Last Modified: 20 Apr 2025

    Double free vulnerability in DfFromLB in docfile.cxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service via a crafted fpx image.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2015-1554

    Last Modified: 20 Apr 2025

    kgb-bot 1.33-2 allows remote attackers to cause a denial of service (crash).

    Published: 28 Aug 2017
    7.5
    High

    CVE-2015-1600

    Last Modified: 20 Apr 2025

    Information disclosure vulnerability in Netatmo Indoor Module firmware 100 and earlier.

    Published: 28 Aug 2017
    4.9
    Medium

    CVE-2017-12076

    Last Modified: 20 Apr 2025

    Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology DiskStation (DSM) before 6.1.1-15088 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-12840

    Last Modified: 20 Apr 2025

    A kernel driver, namely DLMFENC.sys, bundled with the DESLock+ client application 4.8.16 and earlier contains a locally exploitable heap based buffer overflow in the handling of an IOCTL message of type 0x0FA4204. The vulnerability is present due to the kernel driver failing to allocate sufficient memory on the kernel heap to contain a user supplied string as such the string is copied into a buffer of constant size (0x1000-bytes) and thus an overflow condition results. Access to the kernel driver is permitted through an obfuscated interface whereby bytes of user supplied message are "authenticated" via an obfuscation routine employing a linear equation.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12924

    Last Modified: 20 Apr 2025

    CDirVector::GetTable in dirfunc.hxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted fpx image.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2013-7430

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12922

    Last Modified: 20 Apr 2025

    wchar.c in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12923

    Last Modified: 20 Apr 2025

    OLEStream::WriteVT_LPSTR in olestrm.cpp in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12919

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in OLEStream::WriteVT_LPSTR in olestrm.cpp in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service via a crafted fpx image.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12920

    Last Modified: 20 Apr 2025

    CDirectory::GetDirEntry in dir.cxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12921

    Last Modified: 20 Apr 2025

    PFileFlashPixView::GetGlobalInfoProperty in f_fpxvw.cpp in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12954

    Last Modified: 20 Apr 2025

    The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted gig file.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12950

    Last Modified: 20 Apr 2025

    The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12951

    Last Modified: 20 Apr 2025

    The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted gig file.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12952

    Last Modified: 20 Apr 2025

    The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-12953

    Last Modified: 20 Apr 2025

    The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted gig file.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2017-6594

    Last Modified: 20 Apr 2025

    The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2017-9979

    Last Modified: 20 Apr 2025

    On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can leverage this issue by including arbitrary HTML or JavaScript code as a parameter, aka XSS.

    Published: 28 Aug 2017
    4.9
    Medium

    CVE-2017-12077

    Last Modified: 20 Apr 2025

    Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager (SRM) before 1.1.4-6509 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.

    Published: 28 Aug 2017
    5.3
    Medium

    CVE-2017-9978

    Last Modified: 20 Apr 2025

    On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames.

    Published: 28 Aug 2017
    5.4
    Medium

    CVE-2015-3976

    Last Modified: 5 Nov 2025

    Cross-site scripting (XSS) vulnerability in GE Multilink ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multilink ML800/1200/1600/2400 4.2.1 and earlier.

    Published: 28 Aug 2017
    9.8
    Critical

    CVE-2013-0870

    Last Modified: 20 Apr 2025

    The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2012-2805

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in FFMPEG 0.10 allows remote attackers to cause a denial of service.

    Published: 28 Aug 2017
    8.8
    High

    CVE-2014-5302

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code.

    Published: 28 Aug 2017
    8.8
    High

    CVE-2014-9312

    Last Modified: 20 Apr 2025

    Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2015-0974

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in ZTE Datacard MF19 0V1.0.0B04 allows local users to gain privilege by modifying the 'Ucell Internet' directory to reference a malicious mms_dll_r.dll or mediaplayerdll.dll.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2015-1177

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2015-1386

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in unshield 1.0-1.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2014-4925

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40.

    Published: 28 Aug 2017
    8.8
    High

    CVE-2014-5301

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.

    Published: 28 Aug 2017
    9.8
    Critical

    CVE-2014-8426

    Last Modified: 20 Apr 2025

    Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.

    Published: 28 Aug 2017
    9.8
    Critical

    CVE-2014-8428

    Last Modified: 20 Apr 2025

    Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2014-8753

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cit-e-Net Cit-e-Access 6.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2014-8871

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5.3.0.1 and earlier.

    Published: 28 Aug 2017
    8.8
    High

    CVE-2014-8900

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2014-9469

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2014-9483

    Last Modified: 20 Apr 2025

    Emacs 24.4 allows remote attackers to bypass security restrictions.

    Published: 28 Aug 2017