CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2011-4934

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0820. Reason: This candidate is a reservation duplicate of CVE-2012-0820. Notes: All CVE users should reference CVE-2012-0820 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Jul 2017
    Unknown

    CVE-2011-4935

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0821. Reason: This candidate is a reservation duplicate of CVE-2012-0821. Notes: All CVE users should reference CVE-2012-0821 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Jul 2017
    Unknown

    CVE-2011-4936

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-0822. Reason: This candidate is a reservation duplicate of CVE-2012-0822. Notes: All CVE users should reference CVE-2012-0822 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Jul 2017
    Unknown

    CVE-2010-1154

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2010. Notes: none

    Published: 24 Jul 2017
    Unknown

    CVE-2010-2069

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 24 Jul 2017
    Unknown

    CVE-2010-3309

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2010. Notes: none

    Published: 24 Jul 2017
    Unknown

    CVE-2010-1631

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2010. Notes: none

    Published: 24 Jul 2017
    Unknown

    CVE-2010-4244

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-4234. Reason: This candidate is a duplicate of CVE-2010-4234. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2010-4234 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Jul 2017
    9.8
    Critical

    CVE-2015-2279

    Last Modified: 20 Apr 2025

    cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows remote attackers to execute arbitrary OS commands via shell metacharacters after an "&" (ampersand) in the write_mac write_pid, write_msn, write_tan, or write_hdv parameter.

    Published: 24 Jul 2017
    8.8
    High

    CVE-2015-2280

    Last Modified: 20 Apr 2025

    snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709_r1192.pck allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the mac parameter.

    Published: 24 Jul 2017
    7.5
    High

    CVE-2015-1847

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the web request/response interface in Appserver before 1.0.3 allows remote attackers to read normally inaccessible files via a .. (dot dot) in a crafted URL.

    Published: 24 Jul 2017
    6.1
    Medium

    CVE-2017-10711

    Last Modified: 20 Apr 2025

    In SimpleRisk 20170614-001, a CSRF attack on reset.php (aka the Send Password Reset Email form) can insert XSS sequences via the user parameter.

    Published: 24 Jul 2017
    9.8
    Critical

    CVE-2017-11324

    Last Modified: 20 Apr 2025

    An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be triggered via a POST request to /actionphp/action.input.php with the id parameter.

    Published: 24 Jul 2017
    7.5
    High

    CVE-2017-11325

    Last Modified: 20 Apr 2025

    An issue was discovered in Tilde CMS 1.0.1. Arbitrary files can be read via a file=../ attack on actionphp/download.File.php.

    Published: 24 Jul 2017
    7.5
    High

    CVE-2017-11326

    Last Modified: 20 Apr 2025

    An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipulation.

    Published: 24 Jul 2017
    6.5
    Medium

    CVE-2017-11327

    Last Modified: 20 Apr 2025

    An issue was discovered in Tilde CMS 1.0.1. It is possible to retrieve sensitive data by using direct references. A low-privileged user can load PHP resources such as admin/content.php and admin/content.php?method=ftp_upload.

    Published: 24 Jul 2017
    8.8
    High

    CVE-2017-11422

    Last Modified: 20 Apr 2025

    Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods include reset password, create new account, create new role, etc.

    Published: 24 Jul 2017
    6.5
    Medium

    CVE-2017-11608

    Last Modified: 20 Apr 2025

    There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.

    Published: 24 Jul 2017
    6.5
    Medium

    CVE-2017-11605

    Last Modified: 20 Apr 2025

    There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attack.

    Published: 24 Jul 2017
    6.1
    Medium

    CVE-2017-11593

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Markdown Preview Plus extension before 0.5.7 for Chrome allows remote attackers to inject arbitrary web script or HTML into some web applications via the upload and display of crafted text, markdown, or rst files that are designed to be viewed in the browser as plain text, but that will be converted to HTML without proper sanitization.

    Published: 24 Jul 2017
    5.4
    Medium

    CVE-2017-11594

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment.

    Published: 24 Jul 2017
    9.8
    Critical

    CVE-2017-11583

    Last Modified: 20 Apr 2025

    dayrui FineCms 5.0.9 has SQL Injection via the catid parameter in an action=related request to libraries/Template.php.

    Published: 24 Jul 2017
    7.5
    High

    CVE-2017-11587

    Last Modified: 20 Apr 2025

    On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is directory traversal in the filename parameter to the /download.conf URI.

    Published: 24 Jul 2017
    8.8
    High

    CVE-2017-11610

    Last Modified: 20 Apr 2025

    The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

    Published: 24 Jul 2017
    6.7
    Medium

    CVE-2015-5191

    Last Modified: 20 Apr 2025

    VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths under /tmp. Successful exploitation of this issue may result in a local privilege escalation. CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

    Published: 24 Jul 2017
    5.9
    Medium

    CVE-2017-2837

    Last Modified: 21 Nov 2024

    An exploitable denial of service vulnerability exists within the handling of security data in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.

    Published: 24 Jul 2017
    6.1
    Medium

    CVE-2017-11586

    Last Modified: 20 Apr 2025

    dayrui FineCms 5.0.9 has URL Redirector Abuse via the url parameter in a sync action, related to controllers/Weixin.php.

    Published: 24 Jul 2017
    9.8
    Critical

    CVE-2017-11585

    Last Modified: 20 Apr 2025

    dayrui FineCms 5.0.9 has remote PHP code execution via the param parameter in an action=cache request to libraries/Template.php, aka Eval Injection.

    Published: 24 Jul 2017
    6.1
    Medium

    CVE-2017-11581

    Last Modified: 20 Apr 2025

    dayrui FineCms 5.0.9 has Cross Site Scripting (XSS) in admin/Login.php via a payload in the username field that does not begin with a '<' character.

    Published: 24 Jul 2017
    9.8
    Critical

    CVE-2017-11582

    Last Modified: 20 Apr 2025

    dayrui FineCms 5.0.9 has SQL Injection via the num parameter in an action=related or action=tags request to libraries/Template.php.

    Published: 24 Jul 2017
    9.8
    Critical

    CVE-2017-11584

    Last Modified: 20 Apr 2025

    dayrui FineCms 5.0.9 has SQL Injection via the field parameter in an action=module, action=member, action=form, or action=related request to libraries/Template.php.

    Published: 24 Jul 2017
    6.5
    Medium

    CVE-2017-12670

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-3, missing validation was found in coders/mat.c, leading to an assertion failure in the function DestroyImage in MagickCore/image.c, which allows attackers to cause a denial of service.

    Published: 24 Jul 2017
    7
    High

    CVE-2017-2834

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle attack to trigger this vulnerability.

    Published: 24 Jul 2017
    8.1
    High

    CVE-2017-2835

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the RDP receive functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in the middle to trigger this vulnerability.

    Published: 24 Jul 2017
    5.9
    Medium

    CVE-2017-2836

    Last Modified: 21 Nov 2024

    An exploitable denial of service vulnerability exists within the reading of proprietary server certificates in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.

    Published: 24 Jul 2017
    5.9
    Medium

    CVE-2017-2839

    Last Modified: 21 Nov 2024

    An exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.

    Published: 24 Jul 2017
    9.8
    Critical

    CVE-2017-11588

    Last Modified: 20 Apr 2025

    On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is remote command execution via shell metacharacters in the pingAddr parameter to the waitPingqry.cgi URI. The command output is visible at /PingMsg.cmd.

    Published: 24 Jul 2017
    9.8
    Critical

    CVE-2017-11589

    Last Modified: 20 Apr 2025

    On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is no access control for info.html, wancfg.cmd, rtroutecfg.cmd, arpview.cmd, cpuview.cmd, memoryview.cmd, statswan.cmd, statsatm.cmd, scsrvcntr.cmd, scacccntr.cmd, logview.cmd, voicesipview.cmd, usbview.cmd, wlmacflt.cmd, wlwds.cmd, wlstationlist.cmd, HPNAShow.cmd, HPNAView.cmd, qoscls.cmd, qosqueue.cmd, portmap.cmd, scmacflt.cmd, scinflt.cmd, scoutflt.cmd, certlocal.cmd, or certca.cmd.

    Published: 24 Jul 2017
    5.9
    Medium

    CVE-2017-2838

    Last Modified: 21 Nov 2024

    An exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.

    Published: 24 Jul 2017
    7.5
    High

    CVE-2017-11565

    Last Modified: 20 Apr 2025

    debian/tor.init in the Debian tor_0.2.9.11-1~deb9u1 package for Tor was designed to execute aa-exec from the standard system pathname if the apparmor package is installed, but implements this incorrectly (with a wrong assumption that the specific pathname would remain the same forever), which allows attackers to bypass intended AppArmor restrictions by leveraging the silent loss of this protection mechanism. NOTE: this does not affect systems, such as default Debian stretch installations, on which Tor startup relies on a systemd unit file (instead of this tor.init script).

    Published: 23 Jul 2017
    7.5
    High

    CVE-2017-11555

    Last Modified: 20 Apr 2025

    There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.

    Published: 23 Jul 2017
    7.5
    High

    CVE-2017-11556

    Last Modified: 20 Apr 2025

    There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.

    Published: 23 Jul 2017
    Unknown

    CVE-2017-11545

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11543. Reason: This candidate is a duplicate of CVE-2017-11543. Notes: All CVE users should reference CVE-2017-11543 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Jul 2017
    7.5
    High

    CVE-2017-11554

    Last Modified: 20 Apr 2025

    There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.

    Published: 23 Jul 2017
    6.5
    Medium

    CVE-2017-12564

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service.

    Published: 23 Jul 2017
    6.5
    Medium

    CVE-2017-12563

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-2, a memory exhaustion vulnerability was found in the function ReadPSDImage in coders/psd.c, which allows attackers to cause a denial of service.

    Published: 23 Jul 2017
    6.5
    Medium

    CVE-2017-12565

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadOneJNGImage in coders/png.c, which allows attackers to cause a denial of service.

    Published: 23 Jul 2017
    6.5
    Medium

    CVE-2017-12566

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-2, a memory leak vulnerability was found in the function ReadMVGImage in coders/mvg.c, which allows attackers to cause a denial of service, related to the function ReadSVGImage in svg.c.

    Published: 23 Jul 2017
    6.5
    Medium

    CVE-2017-12674

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-2, a CPU exhaustion vulnerability was found in the function ReadPDBImage in coders/pdb.c, which allows attackers to cause a denial of service.

    Published: 23 Jul 2017
    6.5
    Medium

    CVE-2017-13658

    Last Modified: 20 Apr 2025

    In ImageMagick before 6.9.9-3 and 7.x before 7.0.6-3, there is a missing NULL check in the ReadMATImage function in coders/mat.c, leading to a denial of service (assertion failure and application exit) in the DestroyImageInfo function in MagickCore/image.c.

    Published: 23 Jul 2017