CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2015-9022

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, time-of-check Time-of-use (TOCTOU) Race Conditions exist in several TZ APIs.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2015-9020

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in the unlocking of memory.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2015-9021

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2015-9025

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a QTEE application.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2015-9026

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2015-9027

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2015-9028

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a cryptographic routine.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2015-9029

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2015-9030

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, the Hypervisor API could be misused to bypass authentication.

    Published: 13 Jun 2017
    3.3
    Low

    CVE-2015-9031

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a TZ memory address is exposed to HLOS by HDCP.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2016-10337

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2016-10332

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2016-10333

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2016-10334

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2016-10335

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2016-10336

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2016-10340

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability exists in a syscall handler.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2016-10341

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2016-10342

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-7365

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overread can occur if a particular string is not NULL terminated.

    Published: 13 Jun 2017
    5.5
    Medium

    CVE-2017-7366

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-7369

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, an array index in an ALSA routine is not properly validating potentially leading to kernel stack corruption.

    Published: 13 Jun 2017
    7
    High

    CVE-2017-7370

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-7371

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a data pointer is potentially used after it has been freed when SLIMbus is turned off by Bluetooth.

    Published: 13 Jun 2017
    7
    High

    CVE-2017-7372

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-7373

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a double free vulnerability exists in a display driver.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-8234

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, an out of bounds access can potentially occur in a camera function.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-8233

    Last Modified: 20 Apr 2025

    In a camera driver function in all Android releases from CAF using the Linux kernel, a bounds check is missing when writing into an array potentially leading to an out-of-bounds heap write.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-8238

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a camera function.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-8240

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-8241

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a WLAN function due to an incorrect message length.

    Published: 13 Jun 2017
    5.9
    Medium

    CVE-2017-8242

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a race condition exists in a QTEE driver potentially leading to an arbitrary memory write.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-8237

    Last Modified: 20 Apr 2025

    In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists while loading a firmware image.

    Published: 13 Jun 2017
    8.8
    High

    CVE-2016-9984

    Last Modified: 20 Apr 2025

    IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276.

    Published: 13 Jun 2017
    4.3
    Medium

    CVE-2017-1099

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation could expose potentially sensitive information to authenticated users through stack trace error conditions. IBM X-Force ID: 120659.

    Published: 13 Jun 2017
    5.4
    Medium

    CVE-2017-1101

    Last Modified: 20 Apr 2025

    IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120662.

    Published: 13 Jun 2017
    5.4
    Medium

    CVE-2017-1100

    Last Modified: 20 Apr 2025

    IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120661.

    Published: 13 Jun 2017
    5.4
    Medium

    CVE-2017-1104

    Last Modified: 20 Apr 2025

    IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120666.

    Published: 13 Jun 2017
    5.4
    Medium

    CVE-2016-9973

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120209.

    Published: 13 Jun 2017
    5.4
    Medium

    CVE-2017-1102

    Last Modified: 20 Apr 2025

    IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120663.

    Published: 13 Jun 2017
    9.8
    Critical

    CVE-2017-9246

    Last Modified: 20 Apr 2025

    New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES clause of an INSERT statement, after bypassing a SET SHOWPLAN_ALL ON protection mechanism.

    Published: 13 Jun 2017
    8.8
    High

    CVE-2017-9429

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php.

    Published: 13 Jun 2017
    8.8
    High

    CVE-2017-9603

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.

    Published: 13 Jun 2017
    7.5
    High

    CVE-2015-3220

    Last Modified: 20 Apr 2025

    The tlslite library before 0.4.9 for Python allows remote attackers to trigger a denial of service (runtime exception and process crash).

    Published: 13 Jun 2017
    7.8
    High

    CVE-2015-4596

    Last Modified: 30 May 2025

    Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-9552

    Last Modified: 20 Apr 2025

    A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_dsm_user --auth USERNAME PASSWORD", and local users are able to obtain credentials by sniffing "/proc/*/cmdline".

    Published: 13 Jun 2017
    9.8
    Critical

    CVE-2016-6655

    Last Modified: 20 Apr 2025

    An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A command injection vulnerability was discovered in a common script used by many Cloud Foundry components. A malicious user may exploit numerous vectors to execute arbitrary commands on servers running Cloud Foundry.

    Published: 13 Jun 2017
    9.8
    Critical

    CVE-2016-8218

    Last Modified: 20 Apr 2025

    An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.

    Published: 13 Jun 2017
    9.8
    Critical

    CVE-2017-2773

    Last Modified: 20 Apr 2025

    An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23, and 1.9.x versions prior to 1.9.1. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users in multiple components included in PCF Elastic Runtime, aka an "Unauthenticated JWT signing algorithm in multiple components" issue.

    Published: 13 Jun 2017
    9.8
    Critical

    CVE-2017-4955

    Last Modified: 20 Apr 2025

    An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28, and 1.9.x versions prior to 1.9.5. Several credentials were present in the logs for the Notifications errand in the PCF Elastic Runtime tile.

    Published: 13 Jun 2017