CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2017-9525

    Last Modified: 20 Apr 2025

    In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.

    Published: 9 Jun 2017
    4.3
    Medium

    CVE-2016-4909

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors.

    Published: 9 Jun 2017
    5.9
    Medium

    CVE-2016-7805

    Last Modified: 20 Apr 2025

    The mobiGate App for Android version 2.2.1.2 and earlier and mobiGate App for iOS version 2.2.4.1 and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Jun 2017
    6.1
    Medium

    CVE-2016-7813

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in DERAEMON-CMS version 0.8.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the parameters hostname, database and username.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2016-7818

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program Ver. 5.00 and earlier, Device data encryption program Ver. 1.00 and earlier, and TODOKESHO creation program Ver. 15.00 and earlier available prior to October 17, 2016 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 9 Jun 2017
    7.2
    High

    CVE-2016-7819

    Last Modified: 20 Apr 2025

    I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.

    Published: 9 Jun 2017
    6.5
    Medium

    CVE-2016-7821

    Last Modified: 20 Apr 2025

    Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management screen via unspecified vectors.

    Published: 9 Jun 2017
    8.8
    High

    CVE-2016-7830

    Last Modified: 20 Apr 2025

    Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices with firmware version prior to Ver.1.22 allow an attacker on the same network segment to bypass authentication to perform administrative operations via unspecified vectors.

    Published: 9 Jun 2017
    9.1
    Critical

    CVE-2016-7835

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information.

    Published: 9 Jun 2017
    5.4
    Medium

    CVE-2016-7469

    Last Modified: 20 Apr 2025

    A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2, 11.4.0 - 11.6.1, and 11.2.1 allows an authenticated user to inject arbitrary web script or HTML. Exploitation requires Resource Administrator or Administrator privileges, and it could cause the Configuration utility client to become unstable.

    Published: 9 Jun 2017
    2.3
    Low

    CVE-2017-7519

    Last Modified: 21 Nov 2024

    In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.

    Published: 9 Jun 2017
    6.1
    Medium

    CVE-2017-9523

    Last Modified: 20 Apr 2025

    The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.

    Published: 9 Jun 2017
    10
    Critical

    CVE-2015-2692

    Last Modified: 20 Apr 2025

    AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary blocking filters.

    Published: 8 Jun 2017
    7.5
    High

    CVE-2015-3634

    Last Modified: 20 Apr 2025

    The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.

    Published: 8 Jun 2017
    5.4
    Medium

    CVE-2017-1140

    Last Modified: 20 Apr 2025

    IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

    Published: 8 Jun 2017
    6.1
    Medium

    CVE-2015-1588

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server 6 and OX AppSuite before 7.4.2-rev43, 7.6.0-rev38, and 7.6.1-rev21.

    Published: 8 Jun 2017
    8.8
    High

    CVE-2015-1786

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.

    Published: 8 Jun 2017
    7.5
    High

    CVE-2015-3913

    Last Modified: 20 Apr 2025

    The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request message.

    Published: 8 Jun 2017
    8.1
    High

    CVE-2016-6098

    Last Modified: 20 Apr 2025

    IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

    Published: 8 Jun 2017
    4.3
    Medium

    CVE-2016-8987

    Last Modified: 20 Apr 2025

    IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.

    Published: 8 Jun 2017
    8.1
    High

    CVE-2016-9698

    Last Modified: 20 Apr 2025

    IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999960.

    Published: 8 Jun 2017
    5.3
    Medium

    CVE-2016-9736

    Last Modified: 20 Apr 2025

    IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.

    Published: 8 Jun 2017
    7.5
    High

    CVE-2017-1319

    Last Modified: 20 Apr 2025

    IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731.

    Published: 8 Jun 2017
    9.8
    Critical

    CVE-2016-6093

    Last Modified: 20 Apr 2025

    IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.

    Published: 8 Jun 2017
    8
    High

    CVE-2016-9991

    Last Modified: 20 Apr 2025

    IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.

    Published: 8 Jun 2017
    5.9
    Medium

    CVE-2017-1179

    Last Modified: 20 Apr 2025

    IBM BigFix Compliance Analytics 1.9.79 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123431.

    Published: 8 Jun 2017
    7.5
    High

    CVE-2016-6594

    Last Modified: 20 Apr 2025

    Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.

    Published: 8 Jun 2017
    7.5
    High

    CVE-2014-7919

    Last Modified: 20 Apr 2025

    b/libs/gui/ISurfaceComposer.cpp in Android allows attackers to trigger a denial of service (null pointer dereference and process crash).

    Published: 8 Jun 2017
    5.3
    Medium

    CVE-2016-5648

    Last Modified: 20 Apr 2025

    Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.

    Published: 8 Jun 2017
    9.8
    Critical

    CVE-2017-4918

    Last Modified: 20 Apr 2025

    VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX system where the client is installed.

    Published: 8 Jun 2017
    9.8
    Critical

    CVE-2016-2034

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in ClearPass Policy Manager 6.5.x through 6.5.6 and 6.6.0.

    Published: 8 Jun 2017
    7.5
    High

    CVE-2016-3091

    Last Modified: 20 Apr 2025

    Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.

    Published: 8 Jun 2017
    5.3
    Medium

    CVE-2014-4843

    Last Modified: 20 Apr 2025

    Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL.

    Published: 8 Jun 2017
    8.8
    High

    CVE-2015-2252

    Last Modified: 20 Apr 2025

    Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts.

    Published: 8 Jun 2017
    7.5
    High

    CVE-2015-2800

    Last Modified: 20 Apr 2025

    The user authentication module in Huawei Campus switches S5700, S5300, S6300, and S6700 with software before V200R001SPH012 and S7700, S9300, and S9700 with software before V200R001SPH015 allows remote attackers to cause a denial of service (device restart) via vectors involving authentication, which trigger an array access violation.

    Published: 8 Jun 2017
    4.9
    Medium

    CVE-2014-6031

    Last Modified: 20 Apr 2025

    Buffer overflow in the mcpq daemon in F5 BIG-IP systems 10.x before 10.2.4 HF12, 11.x before 11.2.1 HF15, 11.3.x, 11.4.x before 11.4.1 HF9, 11.5.x before 11.5.2 HF1, and 11.6.0 before HF4, and Enterprise Manager 2.1.0 through 2.3.0 and 3.x before 3.1.1 HF5 allows remote authenticated administrators to cause a denial of service via unspecified vectors.

    Published: 8 Jun 2017
    5
    Medium

    CVE-2015-2253

    Last Modified: 20 Apr 2025

    The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.

    Published: 8 Jun 2017
    9.8
    Critical

    CVE-2014-8687

    Last Modified: 20 Apr 2025

    Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.

    Published: 8 Jun 2017
    7.5
    High

    CVE-2015-2251

    Last Modified: 20 Apr 2025

    The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript.

    Published: 8 Jun 2017
    5.9
    Medium

    CVE-2015-2255

    Last Modified: 20 Apr 2025

    Huawei AR1220 routers with software before V200R005SPH006 allow remote attackers to cause a denial of service (board reset) via vectors involving a large amount of traffic from the GE port to the FE port.

    Published: 8 Jun 2017
    9.8
    Critical

    CVE-2017-5878

    Last Modified: 20 Apr 2025

    The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized Java data.

    Published: 8 Jun 2017
    7.8
    High

    CVE-2017-8108

    Last Modified: 20 Apr 2025

    Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a symlink attack on a temporary file.

    Published: 8 Jun 2017
    5.5
    Medium

    CVE-2017-9520

    Last Modified: 20 Apr 2025

    The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file.

    Published: 8 Jun 2017
    8.8
    High

    CVE-2017-9517

    Last Modified: 20 Apr 2025

    atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV.

    Published: 8 Jun 2017
    8.8
    High

    CVE-2017-9518

    Last Modified: 20 Apr 2025

    atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails.

    Published: 8 Jun 2017
    8.8
    High

    CVE-2017-9519

    Last Modified: 20 Apr 2025

    atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account.

    Published: 8 Jun 2017
    7.8
    High

    CVE-2017-4909

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.

    Published: 8 Jun 2017
    7.8
    High

    CVE-2017-4910

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.

    Published: 8 Jun 2017
    9.8
    Critical

    CVE-2017-6640

    Last Modified: 20 Apr 2025

    A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. The account could be granted root- or system-level privileges. The vulnerability exists because the affected software has a default user account that has a default, static password. The user account is created automatically when the software is installed. An attacker could exploit this vulnerability by connecting remotely to an affected system and logging in to the affected software by using the credentials for this default user account. A successful exploit could allow the attacker to use this default user account to log in to the affected software and gain access to the administrative console of a DCNM server. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software releases prior to Release 10.2(1) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd95346.

    Published: 8 Jun 2017
    9.9
    Critical

    CVE-2017-4901

    Last Modified: 20 Apr 2025

    The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 has an out-of-bounds memory access vulnerability. This may allow a guest to execute code on the operating system that runs Workstation or Fusion.

    Published: 8 Jun 2017