CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2014-9513

    Last Modified: 20 Apr 2025

    Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2014-9514

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2014-9557

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2.

    Published: 28 Aug 2017
    9.8
    Critical

    CVE-2014-9558

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in SmartCMS v.2.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2015-0101

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Business Process Manager Standard 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; IBM Business Process Manager Express 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5; and IBM Business Process Manager Advanced 7.5.x before 7.5, 8.0.x before 8.0.1, 8.5.x before 8.5.5.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2015-0114

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in IBM V5R4, and IBM i Access for Windows 6.1 and 7.1.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2015-0928

    Last Modified: 20 Apr 2025

    libhtp 0.5.15 allows remote attackers to cause a denial of service (NULL pointer dereference).

    Published: 28 Aug 2017
    7.5
    High

    CVE-2015-1199

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in ppmd 10.1-5.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2015-1198

    Last Modified: 20 Apr 2025

    Multiple directory traversal vulnerabilities in ha 0.999p+dfsg-5.

    Published: 28 Aug 2017
    9.8
    Critical

    CVE-2015-1401

    Last Modified: 20 Apr 2025

    Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.

    Published: 28 Aug 2017
    9.8
    Critical

    CVE-2015-1430

    Last Modified: 20 Apr 2025

    Buffer overflow in xymon 4.3.17-1.

    Published: 28 Aug 2017
    8.8
    High

    CVE-2015-1443

    Last Modified: 20 Apr 2025

    The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code.

    Published: 28 Aug 2017
    7.2
    High

    CVE-2015-1445

    Last Modified: 20 Apr 2025

    HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2015-1876

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in ES File Explorer 3.2.4.1.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2015-2046

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later before 1.2.20.

    Published: 28 Aug 2017
    5.5
    Medium

    CVE-2017-14228

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference. It will lead to remote denial of service.

    Published: 28 Aug 2017
    5.3
    Medium

    CVE-2017-3735

    Last Modified: 20 Apr 2025

    While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.

    Published: 28 Aug 2017
    5.5
    Medium

    CVE-2017-15116

    Last Modified: 20 Apr 2025

    The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).

    Published: 28 Aug 2017
    5.5
    Medium

    CVE-2017-10689

    Last Modified: 21 Nov 2024

    In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

    Published: 28 Aug 2017
    9.8
    Critical

    CVE-2017-11462

    Last Modified: 20 Apr 2025

    Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.

    Published: 28 Aug 2017
    5.5
    Medium

    CVE-2017-13685

    Last Modified: 20 Apr 2025

    The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a denial of service (EXC_BAD_ACCESS and application crash) via a crafted file.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-14497

    Last Modified: 20 Apr 2025

    The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified other impact via crafted system calls.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2017-14063

    Last Modified: 20 Apr 2025

    Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.

    Published: 28 Aug 2017
    7.5
    High

    CVE-2017-13709

    Last Modified: 20 Apr 2025

    In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the contents of the global Property Tree.

    Published: 27 Aug 2017
    9.8
    Critical

    CVE-2017-13707

    Last Modified: 20 Apr 2025

    Privilege escalation in Replibit Backup Manager earlier than version 2017.08.04 allows attackers to gain root privileges via sudo command execution. The vi program can be accessed through sudo, in order to navigate the filesystem and modify a critical file such as /etc/passwd.

    Published: 27 Aug 2017
    5.5
    Medium

    CVE-2017-14489

    Last Modified: 20 Apr 2025

    The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (panic) by leveraging incorrect length validation.

    Published: 27 Aug 2017
    5.5
    Medium

    CVE-2017-18185

    Last Modified: 21 Nov 2024

    An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.

    Published: 27 Aug 2017
    7.5
    High

    CVE-2017-0379

    Last Modified: 20 Apr 2025

    Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

    Published: 27 Aug 2017
    6.5
    Medium

    CVE-2017-7693

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated users to inject arbitrary commands to read OS files.

    Published: 26 Aug 2017
    8.8
    High

    CVE-2017-14176

    Last Modified: 20 Apr 2025

    Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.

    Published: 26 Aug 2017
    7.8
    High

    CVE-2017-17052

    Last Modified: 20 Apr 2025

    The mm_init function in kernel/fork.c in the Linux kernel before 4.12.10 does not clear the ->exe_file member of a new process's mm_struct, allowing a local attacker to achieve a use-after-free or possibly have unspecified other impact by running a specially crafted program.

    Published: 26 Aug 2017
    7.5
    High

    CVE-2017-12817

    Last Modified: 20 Apr 2025

    In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.

    Published: 25 Aug 2017
    9.8
    Critical

    CVE-2017-12816

    Last Modified: 20 Apr 2025

    In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the product functionality by using Android IPC.

    Published: 25 Aug 2017
    7.5
    High

    CVE-2017-12694

    Last Modified: 20 Apr 2025

    A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files.

    Published: 25 Aug 2017
    7
    High

    CVE-2017-9644

    Last Modified: 20 Apr 2025

    An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.

    Published: 25 Aug 2017
    9.8
    Critical

    CVE-2017-12707

    Last Modified: 20 Apr 2025

    A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Opening a maliciously crafted html file may cause a stack overflow.

    Published: 25 Aug 2017
    8.8
    High

    CVE-2017-12857

    Last Modified: 20 Apr 2025

    Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a segment of the phone's memory which could contain an administrator's password or other sensitive information.

    Published: 25 Aug 2017
    7.4
    High

    CVE-2017-7930

    Last Modified: 20 Apr 2025

    An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws with the potential to expose change records in the clear and allow a malicious party to spoof a server within a collective.

    Published: 25 Aug 2017
    5.9
    Medium

    CVE-2017-7934

    Last Modified: 20 Apr 2025

    An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older protocol versions contains a flaw that could allow a malicious user to authenticate with a server and then cause PI Network Manager to behave in an undefined manner.

    Published: 25 Aug 2017
    6.3
    Medium

    CVE-2017-9640

    Last Modified: 20 Apr 2025

    A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.

    Published: 25 Aug 2017
    8.8
    High

    CVE-2017-7926

    Last Modified: 20 Apr 2025

    A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0). The vulnerability allows cross-site request forgery (CSRF) attacks to occur when an otherwise-unauthorized cross-site request is sent from a browser the server has previously authenticated.

    Published: 25 Aug 2017
    7.8
    High

    CVE-2017-9650

    Last Modified: 20 Apr 2025

    An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code.

    Published: 25 Aug 2017
    7
    High

    CVE-2015-1325

    Last Modified: 3 Nov 2025

    Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files and gain root privileges.

    Published: 25 Aug 2017
    9.8
    Critical

    CVE-2014-7857

    Last Modified: 20 Apr 2025

    D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and log in with administrator permissions by passing the cgi_set_wto command in the cmd parameter, and setting the spawned session's cookie to username=admin.

    Published: 25 Aug 2017
    9.8
    Critical

    CVE-2014-7859

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-326 before 2.10 build 03, and DNS-327L before 1.04b01 allows remote attackers to execute arbitrary code by crafting malformed "Host" and "Referer" header values.

    Published: 25 Aug 2017
    5.3
    Medium

    CVE-2014-7860

    Last Modified: 20 Apr 2025

    The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos and publish them to an arbitrary Facebook profile via a target album_id and access_token.

    Published: 25 Aug 2017
    6.1
    Medium

    CVE-2014-9564

    Last Modified: 20 Apr 2025

    CRLF injection vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware before 3.4.1110 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks and resulting web cache poisoning or cross-site scripting (XSS) attacks, or obtain sensitive information via multiple unspecified parameters.

    Published: 25 Aug 2017
    9.8
    Critical

    CVE-2014-7858

    Last Modified: 20 Apr 2025

    The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username cookie parameter to an arbitrary string.

    Published: 25 Aug 2017
    7.8
    High

    CVE-2015-1324

    Last Modified: 20 Apr 2025

    Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files and gain root privileges by leveraging incorrect handling of permissions when generating core dumps for setuid binaries.

    Published: 25 Aug 2017
    6.1
    Medium

    CVE-2015-3257

    Last Modified: 20 Apr 2025

    Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.

    Published: 25 Aug 2017