CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2016-7831

    Last Modified: 20 Apr 2025

    Sleipnir 4 Black Edition for Mac 4.5.3 and earlier and Sleipnir 4 for Mac 4.5.3 and earlier (Mac App Store) may allow a remote attacker to spoof the URL display via a specially crafted webpage.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2017-2182

    Last Modified: 20 Apr 2025

    Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors, a different vulnerability than CVE-2017-2179 and CVE-2017-2181.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2189

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in RW-4040 driver installer for Windows 7 version 2.27 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2191

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2017-2207

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in the installer of SaAT Personal ver.1.0.10.272 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    7.2
    High

    CVE-2016-7820

    Last Modified: 20 Apr 2025

    Buffer overflow in I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to cause a denial-of-service (DoS) or execute arbitrary code via unspecified vectors.

    Published: 9 Jun 2017
    6.5
    Medium

    CVE-2016-7826

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted POST requests.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2016-4902

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.0.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)" Ver3.0.1 and earlier and The Public Certification Service for Individuals "The JPKI user's software" Ver2.6 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    4.3
    Medium

    CVE-2016-4908

    Last Modified: 20 Apr 2025

    Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.

    Published: 9 Jun 2017
    4.3
    Medium

    CVE-2017-2180

    Last Modified: 20 Apr 2025

    Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2017-2181

    Last Modified: 20 Apr 2025

    Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors, a different vulnerability than CVE-2017-2179 and CVE-2017-2182.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2017-2206

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in the installer of SaAT Netizen ver.1.2.10.510 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2209

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in the installer of Houkokusyo Sakusei Shien Tool ver3.0.2 (For the first installation) (The version which was available on the website from 2017 April 4 to 2017 May 18) and ver2.0 and later (For the first installation) (The versions which were available on the website prior to 2017 April 4) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    8.4
    High

    CVE-2017-2214

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in AppCheck and AppCheck Pro prior to version 2.0.1.15 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.

    Published: 9 Jun 2017
    6.1
    Medium

    CVE-2016-4906

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2016-4907

    Last Modified: 20 Apr 2025

    Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.

    Published: 9 Jun 2017
    4.3
    Medium

    CVE-2016-4910

    Last Modified: 20 Apr 2025

    Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2016-7803

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function.

    Published: 9 Jun 2017
    6.5
    Medium

    CVE-2016-7802

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to read arbitrary files via unspecified vectors.

    Published: 9 Jun 2017
    4.3
    Medium

    CVE-2016-7801

    Last Modified: 20 Apr 2025

    Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via unspecified vectors.

    Published: 9 Jun 2017
    9.8
    Critical

    CVE-2016-7806

    Last Modified: 20 Apr 2025

    I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 9 Jun 2017
    7.5
    High

    CVE-2016-7807

    Last Modified: 20 Apr 2025

    I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to bypass access restriction to access data on storage devices inserted into the product via unspecified vectors.

    Published: 9 Jun 2017
    6.1
    Medium

    CVE-2016-7808

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2016-7809

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows remote attackers to hijack the authentication of logged in user to conduct unintended operations via unspecified vectors.

    Published: 9 Jun 2017
    4.8
    Medium

    CVE-2016-7810

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2016-7811

    Last Modified: 20 Apr 2025

    Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary operations via unspecified vectors.

    Published: 9 Jun 2017
    7.5
    High

    CVE-2016-7814

    Last Modified: 20 Apr 2025

    I-O DATA DEVICE TS-WRLP firmware version 1.00.01 and earlier and TS-WRLA firmware version 1.00.01 and earlier allow remote attackers to obtain authentication credentials via unspecified vectors.

    Published: 9 Jun 2017
    5.9
    Medium

    CVE-2016-7816

    Last Modified: 20 Apr 2025

    The Cybozu kintone mobile for Android 1.0.6 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Jun 2017
    6.1
    Medium

    CVE-2016-7817

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Simple keitai chat 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2016-7822

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackers to hijack the authentication of a logged in user to perform unintended operations via unspecified vectors.

    Published: 9 Jun 2017
    4.3
    Medium

    CVE-2016-7823

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2016-7824

    Last Modified: 20 Apr 2025

    Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the debug option via unspecified vectors.

    Published: 9 Jun 2017
    6.5
    Medium

    CVE-2016-7825

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted commands.

    Published: 9 Jun 2017
    5.3
    Medium

    CVE-2016-7832

    Last Modified: 20 Apr 2025

    Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to obtain an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors.

    Published: 9 Jun 2017
    7.5
    High

    CVE-2016-7833

    Last Modified: 20 Apr 2025

    Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors.

    Published: 9 Jun 2017
    6.5
    Medium

    CVE-2017-2165

    Last Modified: 20 Apr 2025

    GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as emails via unspecified vectors.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2176

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in screensaver installers (jasdf_01.exe, jasdf_02.exe, jasdf_03.exe, jasdf_04.exe, jasdf_05.exe, scramble_setup.exe, clock_01_setup.exe, clock_02_setup.exe) available prior to May 25, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2017-2177

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Installer of Shogyo Touki Denshi Ninsho Software Ver 1.7 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2017-2178

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Installer of electronic tendering and bid opening system available prior to May 25, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2017-2179

    Last Modified: 20 Apr 2025

    Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allows remote code execution via unspecified vectors, a different vulnerability than CVE-2017-2181 and CVE-2017-2182.

    Published: 9 Jun 2017
    6.1
    Medium

    CVE-2017-2187

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2190

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in RW-4040 tool to verify execution environment for Windows 7 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2192

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in RW-5100 tool to verify execution environment for Windows 7 version 1.1.0.0 and RW-5100 tool to verify execution environment for Windows 8.1 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2193

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in the installer of Tera Term 4.94 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2017-2195

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the Multi Feed Reader prior to version 2.2.4 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2210

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in PatchJGD (PatchJGD101.EXE) ver. 1.0.1 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2211

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in PatchJGD (Hyoko) (PatchJGDh101.EXE) ver. 1.0.1 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2212

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in TKY2JGD (TKY2JGD1379.EXE) ver. 1.3.79 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2213

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in SemiDynaEXE (SemiDynaEXE2008.EXE) ver. 1.0.2 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2017-2219

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in the [Simeji for Windows] installer (simeji.exe) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017