CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2012-5030

    Last Modified: 20 Apr 2025

    Cisco IOS before 15.2(4)S6 does not initialize an unspecified variable, which might allow remote authenticated users to cause a denial of service (CPU consumption, watchdog timeout, crash) by walking specific SNMP objects.

    Published: 2 Aug 2017
    6.5
    Medium

    CVE-2015-0194

    Last Modified: 20 Apr 2025

    XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers to read arbitrary files via a crafted XML data.

    Published: 2 Aug 2017
    6.1
    Medium

    CVE-2015-2690

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in views/add-license-form.php in the Digium Addons module (digiumaddoninstaller) before 2.11.0.7 for FreePBX allow remote attackers to inject arbitrary web script or HTML via the (1) add_license_key, (2) add_license_first_name, (3) add_license_last_name, (4) add_license_company, (5) add_license_address1, (6) add_license_address2, (7) add_license_city, (8) add_license_state, (9) add_license_post_code, (10) add_license_country, (11) add_license_phone, or (12) add_license_email parameter in an add-license-form page to admin/config.php.

    Published: 2 Aug 2017
    9.8
    Critical

    CVE-2017-9769

    Last Modified: 20 Apr 2025

    A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process.

    Published: 2 Aug 2017
    8.8
    High

    CVE-2014-8903

    Last Modified: 20 Apr 2025

    IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.

    Published: 2 Aug 2017
    9.8
    Critical

    CVE-2015-1174

    Last Modified: 20 Apr 2025

    Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.

    Published: 2 Aug 2017
    9.8
    Critical

    CVE-2015-2560

    Last Modified: 20 Apr 2025

    Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.

    Published: 2 Aug 2017
    7
    High

    CVE-2015-7891

    Last Modified: 20 Apr 2025

    Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory errors by leveraging definition of g2d_lock and g2d_unlock lock macros as no-ops, aka SVE-2015-4598.

    Published: 2 Aug 2017
    6.5
    Medium

    CVE-2017-11437

    Last Modified: 20 Apr 2025

    GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.

    Published: 2 Aug 2017
    6.3
    Medium

    CVE-2017-11438

    Last Modified: 20 Apr 2025

    GitLab Community Edition (CE) and Enterprise Edition (EE) before 9.0.11, 9.1.8, 9.2.8 allow an authenticated user with the ability to create a group to add themselves to any project that is inside a subgroup.

    Published: 2 Aug 2017
    7.8
    High

    CVE-2017-7642

    Last Modified: 20 Apr 2025

    The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local users to gain root privileges by leveraging failure to verify the path to the encoded ruby script or scrub the PATH variable.

    Published: 2 Aug 2017
    9.8
    Critical

    CVE-2017-8390

    Last Modified: 20 Apr 2025

    The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via a crafted domain name.

    Published: 2 Aug 2017
    7.8
    High

    CVE-2017-9247

    Last Modified: 20 Apr 2025

    Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to launch processes with elevated privileges.

    Published: 2 Aug 2017
    6.1
    Medium

    CVE-2017-9459

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Aug 2017
    6.1
    Medium

    CVE-2017-9467

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Aug 2017
    6.1
    Medium

    CVE-2017-11355

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to the main page; the (2) beanReference parameter to the JavaBean viewer page; or the (3) pyTableName to the System database schema modification page.

    Published: 2 Aug 2017
    6.5
    Medium

    CVE-2017-11356

    Last Modified: 20 Apr 2025

    The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control.

    Published: 2 Aug 2017
    6.1
    Medium

    CVE-2017-9244

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Trello app before 4.0.8 for iOS might allow remote attackers to inject arbitrary web script or HTML by uploading and attaching a crafted photo to a Card.

    Published: 2 Aug 2017
    5.5
    Medium

    CVE-2017-9770

    Last Modified: 20 Apr 2025

    A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse that can cause an out of bounds read operation to occur due to a field within the IOCTL data being used as a length.

    Published: 2 Aug 2017
    8.1
    High

    CVE-2016-9981

    Last Modified: 20 Apr 2025

    IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an attacker to hijack a valid user's session. IBM X-Force ID: 120257

    Published: 2 Aug 2017
    8.1
    High

    CVE-2017-1467

    Last Modified: 20 Apr 2025

    A network layer security vulnerability in InfoSphere Information Server 9.1, 11.3, and 11.5 can lead to privilege escalation or unauthorized access. IBM X-Force ID: 128466.

    Published: 2 Aug 2017
    7.8
    High

    CVE-2017-1468

    Last Modified: 20 Apr 2025

    IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-force ID: 128467.

    Published: 2 Aug 2017
    7.5
    High

    CVE-2017-1118

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ Internet Pass-Thru 2.0 and 2.1 could allow n attacker to cause the MQIPT to stop responding due to an incorrectly configured security policy. IBM X-Force ID: 121156.

    Published: 2 Aug 2017
    9.1
    Critical

    CVE-2017-1383

    Last Modified: 20 Apr 2025

    IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 127155.

    Published: 2 Aug 2017
    4.9
    Medium

    CVE-2017-1495

    Last Modified: 20 Apr 2025

    IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a privileged user to cause a memory dump that could contain highly sensitive information including access credentials. IBM X-Force ID: 128693.

    Published: 2 Aug 2017
    8
    High

    CVE-2017-2283

    Last Modified: 20 Apr 2025

    WN-G300R3 firmware version 1.0.2 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device.

    Published: 2 Aug 2017
    6.1
    Medium

    CVE-2017-2285

    Last Modified: 6 May 2025

    Cross-site scripting vulnerability in Simple Custom CSS and JS prior to version 3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Aug 2017
    7.8
    High

    CVE-2017-2287

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in NFC Port Software remover Ver.1.3.0.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 2 Aug 2017
    3.1
    Low

    CVE-2016-7812

    Last Modified: 20 Apr 2025

    The Bank of Tokyo-Mitsubishi UFJ, Ltd. App for Android ver5.3.1, ver5.2.2 and earlier allow a man-in-the-middle attacker to downgrade the communication between the app and the server from TLS v1.2 to SSL v3.0, which may result in the attacker to eavesdrop on an encrypted communication.

    Published: 2 Aug 2017
    6.8
    Medium

    CVE-2017-2282

    Last Modified: 20 Apr 2025

    Buffer overflow in WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.

    Published: 2 Aug 2017
    7.8
    High

    CVE-2017-2286

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in NFC Port Software Version 5.5.0.6 and earlier (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S), NFC Port Software Version 5.3.6.7 and earlier (for RC-S320, RC-S310/J1C, RC-S310/ED4C), PC/SC Activator for Type B Ver.1.2.1.0 and earlier, SFCard Viewer 2 Ver.2.5.0.0 and earlier, NFC Net Installer Ver.1.1.0.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 2 Aug 2017
    7.8
    High

    CVE-2017-2288

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in LhaForge Ver.1.6.5 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 2 Aug 2017
    6.5
    Medium

    CVE-2016-7845

    Last Modified: 20 Apr 2025

    GigaCC OFFICE ver.2.3 and earlier allows remote attackers to upload arbitrary files as a user profile image, which may be exploited for unauthorized file sharing.

    Published: 2 Aug 2017
    8.8
    High

    CVE-2017-2138

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 2 Aug 2017
    5.9
    Medium

    CVE-2017-2278

    Last Modified: 20 Apr 2025

    The RBB SPEED TEST App for Android version 2.0.3 and earlier, RBB SPEED TEST App for iOS version 2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Aug 2017
    7.8
    High

    CVE-2017-2279

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Tween Ver1.6.6.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 2 Aug 2017
    8.8
    High

    CVE-2017-2280

    Last Modified: 20 Apr 2025

    WN-AX1167GR firmware version 3.00 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device.

    Published: 2 Aug 2017
    8.8
    High

    CVE-2017-2281

    Last Modified: 20 Apr 2025

    WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

    Published: 2 Aug 2017
    6.1
    Medium

    CVE-2017-2284

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Aug 2017
    5.5
    Medium

    CVE-2016-7844

    Last Modified: 20 Apr 2025

    GigaCC OFFICE ver.2.3 and earlier allows remote attackers to execute arbitrary OS commands via specially crafted mail template.

    Published: 2 Aug 2017
    9.8
    Critical

    CVE-2017-11494

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a login action.

    Published: 2 Aug 2017
    8.8
    High

    CVE-2017-11364

    Last Modified: 20 Apr 2025

    The CMS installer in Joomla! before 3.7.4 does not verify a user's ownership of a webspace, which allows remote authenticated users to gain control of the target application by leveraging Certificate Transparency logs.

    Published: 2 Aug 2017
    6.1
    Medium

    CVE-2017-12138

    Last Modified: 20 Apr 2025

    XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.

    Published: 2 Aug 2017
    6.5
    Medium

    CVE-2017-12143

    Last Modified: 20 Apr 2025

    In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 2 Aug 2017
    6.1
    Medium

    CVE-2017-12200

    Last Modified: 20 Apr 2025

    The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.

    Published: 2 Aug 2017
    5.5
    Medium

    CVE-2017-12141

    Last Modified: 20 Apr 2025

    In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 2 Aug 2017
    5.5
    Medium

    CVE-2017-12142

    Last Modified: 20 Apr 2025

    In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 2 Aug 2017
    6.1
    Medium

    CVE-2017-12139

    Last Modified: 20 Apr 2025

    XOOPS Core 2.5.8 has stored XSS in imagemanager.php because of missing MIME type validation in htdocs/class/uploader.php.

    Published: 2 Aug 2017
    5.5
    Medium

    CVE-2017-12144

    Last Modified: 20 Apr 2025

    In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 2 Aug 2017
    6.5
    Medium

    CVE-2017-12145

    Last Modified: 20 Apr 2025

    In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 2 Aug 2017