CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2017-1157

    Last Modified: 20 Apr 2025

    IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could allow an authenticated attacker to access report data that should be restricted to authorized users. IBM X-Force ID: 122788.

    Published: 5 Jul 2017
    9.9
    Critical

    CVE-2017-1253

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 124633.

    Published: 5 Jul 2017
    7.1
    High

    CVE-2017-1254

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 124634.

    Published: 5 Jul 2017
    5.4
    Medium

    CVE-2016-9986

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120552.

    Published: 5 Jul 2017
    5.4
    Medium

    CVE-2016-9733

    Last Modified: 20 Apr 2025

    IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119762.

    Published: 5 Jul 2017
    5.4
    Medium

    CVE-2017-1113

    Last Modified: 20 Apr 2025

    IBM Rational Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 121151.

    Published: 5 Jul 2017
    5.4
    Medium

    CVE-2016-9746

    Last Modified: 20 Apr 2025

    IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119821.

    Published: 5 Jul 2017
    9.8
    Critical

    CVE-2017-1175

    Last Modified: 20 Apr 2025

    IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123297.

    Published: 5 Jul 2017
    5.4
    Medium

    CVE-2016-9701

    Last Modified: 20 Apr 2025

    IBM Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119529.

    Published: 5 Jul 2017
    3.3
    Low

    CVE-2017-1176

    Last Modified: 20 Apr 2025

    IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local user to obtain sensitive information due to inappropriate data retention of attachments. IBM X-Force ID: 123299.

    Published: 5 Jul 2017
    5.5
    Medium

    CVE-2017-1207

    Last Modified: 20 Apr 2025

    IBM WebSphere Message Broker stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123777.

    Published: 5 Jul 2017
    5.4
    Medium

    CVE-2017-1208

    Last Modified: 20 Apr 2025

    IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123778.

    Published: 5 Jul 2017
    7.5
    High

    CVE-2017-2294

    Last Modified: 20 Apr 2025

    Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.6), so key values could be logged and stored in PuppetDB. These releases use the sensitive data type to ensure this won't happen anymore.

    Published: 5 Jul 2017
    6.1
    Medium

    CVE-2017-1256

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0, 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124678

    Published: 5 Jul 2017
    3.7
    Low

    CVE-2016-0238

    Last Modified: 20 Apr 2025

    IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409

    Published: 5 Jul 2017
    6.1
    Medium

    CVE-2017-1217

    Last Modified: 20 Apr 2025

    IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123857

    Published: 5 Jul 2017
    6.5
    Medium

    CVE-2017-1258

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685

    Published: 5 Jul 2017
    9.8
    Critical

    CVE-2017-1269

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 124744

    Published: 5 Jul 2017
    7.8
    High

    CVE-2017-10929

    Last Modified: 20 Apr 2025

    The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in the grub_disk_read_small_real function in kern/disk.c in GNU GRUB 2.02.

    Published: 5 Jul 2017
    8.8
    High

    CVE-2017-10928

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

    Published: 5 Jul 2017
    9.8
    Critical

    CVE-2017-10965

    Last Modified: 20 Apr 2025

    An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.

    Published: 5 Jul 2017
    9.8
    Critical

    CVE-2017-10966

    Last Modified: 20 Apr 2025

    An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.

    Published: 5 Jul 2017
    6.5
    Medium

    CVE-2017-10803

    Last Modified: 20 Apr 2025

    In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.

    Published: 4 Jul 2017
    9.8
    Critical

    CVE-2017-10804

    Last Modified: 20 Apr 2025

    In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.

    Published: 4 Jul 2017
    8.8
    High

    CVE-2017-10805

    Last Modified: 20 Apr 2025

    In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users.

    Published: 4 Jul 2017
    6.1
    Medium

    CVE-2017-7276

    Last Modified: 20 Apr 2025

    There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019.

    Published: 4 Jul 2017
    9.8
    Critical

    CVE-2017-10807

    Last Modified: 20 Apr 2025

    JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.

    Published: 4 Jul 2017
    6.1
    Medium

    CVE-2017-7316

    Last Modified: 20 Apr 2025

    An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page.

    Published: 4 Jul 2017
    9.8
    Critical

    CVE-2017-7317

    Last Modified: 20 Apr 2025

    An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka GatewaySettings.bin.

    Published: 4 Jul 2017
    9.8
    Critical

    CVE-2017-7315

    Last Modified: 20 Apr 2025

    An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router credentials are stored in plaintext inside the backup, aka GatewaySettings.bin.

    Published: 4 Jul 2017
    6.1
    Medium

    CVE-2017-9313

    Last Modified: 20 Apr 2025

    Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary web script or HTML via the sec parameter to view_man.cgi, the referers parameter to change_referers.cgi, or the name parameter to save_user.cgi. NOTE: these issues were not fixed in 1.840.

    Published: 4 Jul 2017
    5.4
    Medium

    CVE-2017-6605

    Last Modified: 20 Apr 2025

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a reflective cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc85415. Known Affected Releases: 2.1(0.800).

    Published: 4 Jul 2017
    5.5
    Medium

    CVE-2017-6705

    Last Modified: 20 Apr 2025

    A vulnerability in the filesystem of the Cisco Prime Collaboration Provisioning tool could allow an authenticated, local attacker to acquire sensitive information. More Information: CSCvc82973. Known Affected Releases: 12.1.

    Published: 4 Jul 2017
    5.4
    Medium

    CVE-2017-6717

    Last Modified: 20 Apr 2025

    A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. More Information: CSCvc38801. Known Affected Releases: 6.0.1.3 6.2.1. Known Fixed Releases: 6.2.1.

    Published: 4 Jul 2017
    5.5
    Medium

    CVE-2017-10995

    Last Modified: 20 Apr 2025

    The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image.

    Published: 4 Jul 2017
    5.8
    Medium

    CVE-2017-3865

    Last Modified: 20 Apr 2025

    A vulnerability in the IPsec component of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and prevent new tunnels from establishing, resulting in a denial of service (DoS) condition. Affected Products: ASR 5000 Series Routers, Virtualized Packet Core (VPC) Software. More Information: CSCvc21129. Known Affected Releases: 21.1.0 21.1.M0.65601 21.1.v0. Known Fixed Releases: 21.2.A0.65754 21.1.b0.66164 21.1.V0.66014 21.1.R0.65759 21.1.M0.65749 21.1.0.66030 21.1.0.

    Published: 4 Jul 2017
    6.1
    Medium

    CVE-2017-6700

    Last Modified: 20 Apr 2025

    A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a Document Object Model (DOM) based (environment or client-side) cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc24620 CSCvc49586. Known Affected Releases: 3.1(1) 2.0(4.0.45B).

    Published: 4 Jul 2017
    6.1
    Medium

    CVE-2017-6701

    Last Modified: 20 Apr 2025

    A vulnerability in the web application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvd49141. Known Affected Releases: 2.1(102.101).

    Published: 4 Jul 2017
    6.1
    Medium

    CVE-2017-6702

    Last Modified: 20 Apr 2025

    A vulnerability in the web framework of Cisco SocialMiner could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCve15285. Known Affected Releases: 11.5(1).

    Published: 4 Jul 2017
    5.9
    Medium

    CVE-2017-6703

    Last Modified: 20 Apr 2025

    A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, remote attacker to hijack another user's session. More Information: CSCvc90346. Known Affected Releases: 12.1.

    Published: 4 Jul 2017
    6.5
    Medium

    CVE-2017-6704

    Last Modified: 20 Apr 2025

    A vulnerability in the web application in the Cisco Prime Collaboration Provisioning tool could allow an authenticated, remote attacker to perform arbitrary file downloads that could allow the attacker to read files from the underlying filesystem. More Information: CSCvc90335. Known Affected Releases: 12.1.

    Published: 4 Jul 2017
    5.4
    Medium

    CVE-2017-6715

    Last Modified: 20 Apr 2025

    A vulnerability in the web framework of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. Affected Products: Cisco Firepower Management Center Releases 5.4.1.x and prior. More Information: CSCuy88951. Known Affected Releases: 5.4.1.6.

    Published: 4 Jul 2017
    5.4
    Medium

    CVE-2017-6716

    Last Modified: 20 Apr 2025

    A vulnerability in the web framework code of Cisco Firepower Management Center could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. Affected Products: Cisco Firepower Management Center Software Releases prior to 6.0.0.0. More Information: CSCuy88785. Known Affected Releases: 5.4.1.6.

    Published: 4 Jul 2017
    6.7
    Medium

    CVE-2017-6719

    Last Modified: 20 Apr 2025

    A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.1.28i.BASE 6.2.1.22i.BASE 6.1.32.8i.BASE 6.1.31.3i.BASE 6.1.3.10i.BASE.

    Published: 4 Jul 2017
    6.1
    Medium

    CVE-2017-6722

    Last Modified: 20 Apr 2025

    A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases: 10.6(1). Known Fixed Releases: 11.5(1.10000.61).

    Published: 4 Jul 2017
    9.1
    Critical

    CVE-2017-7544

    Last Modified: 20 Apr 2025

    libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data of an ExifMnote entry which can cause denial-of-service or possibly information disclosure.

    Published: 4 Jul 2017
    5.4
    Medium

    CVE-2017-6698

    Last Modified: 20 Apr 2025

    A vulnerability in the Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) SQL database interface could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc23892 CSCvc35270 CSCvc35626 CSCvc35630 CSCvc49568. Known Affected Releases: 3.1(1) 2.0(4.0.45B).

    Published: 4 Jul 2017
    6.1
    Medium

    CVE-2017-6699

    Last Modified: 20 Apr 2025

    A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc24616 CSCvc35363 CSCvc49574. Known Affected Releases: 3.1(1) 2.0(4.0.45B).

    Published: 4 Jul 2017
    5.1
    Medium

    CVE-2017-6706

    Last Modified: 20 Apr 2025

    A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire sensitive information. More Information: CSCvd07260. Known Affected Releases: 12.1.

    Published: 4 Jul 2017
    6.7
    Medium

    CVE-2017-6718

    Last Modified: 20 Apr 2025

    A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb99384. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.11.3i.ROUT 6.2.1.29i.ROUT 6.2.1.26i.ROUT.

    Published: 4 Jul 2017