CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-7824

    Last Modified: 20 Apr 2025

    botan 1.11.x before 1.11.22 makes it easier for remote attackers to decrypt TLS ciphertext data via a padding-oracle attack against TLS CBC ciphersuites.

    Published: 10 Apr 2017
    4.9
    Medium

    CVE-2016-10310

    Last Modified: 20 Apr 2025

    Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remote authenticated users to cause a denial of service (resource consumption and process crash) by sending a crafted packet several times, aka SAP Security Note 2308778.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2016-6878

    Last Modified: 20 Apr 2025

    The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to have unspecified impact via vectors related to undefined behavior, as demonstrated on 32-bit ARM systems compiled by Clang.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2016-6879

    Last Modified: 20 Apr 2025

    The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call with more than one Key_Usage set in the enum value.

    Published: 10 Apr 2017
    3.5
    Low

    CVE-2017-5607

    Last Modified: 20 Apr 2025

    Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2017-5983

    Last Modified: 20 Apr 2025

    The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2017-5988

    Last Modified: 20 Apr 2025

    NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2017-7185

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2017-7239

    Last Modified: 20 Apr 2025

    Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.

    Published: 10 Apr 2017
    5.3
    Medium

    CVE-2017-7345

    Last Modified: 20 Apr 2025

    NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Method Invocation (aka JMX RMI) service to the network, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2016-10321

    Last Modified: 20 Apr 2025

    web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2015-8378

    Last Modified: 20 Apr 2025

    In KeePassX before 0.4.4, a cleartext copy of password data is created upon a cancel of an XML export action. This allows context-dependent attackers to obtain sensitive information by reading the .xml dotfile.

    Published: 10 Apr 2017
    6.5
    Medium

    CVE-2016-10304

    Last Modified: 20 Apr 2025

    The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service (out-of-memory error and service instability) via a crafted serialized Java object, as demonstrated by serial.cc3, aka SAP Security Note 2315788.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2016-6605

    Last Modified: 20 Apr 2025

    Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2017-6190

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.

    Published: 10 Apr 2017
    8.8
    High

    CVE-2017-7617

    Last Modified: 20 Apr 2025

    Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action.

    Published: 10 Apr 2017
    8.8
    High

    CVE-2015-2880

    Last Modified: 20 Apr 2025

    TRENDnet WiFi Baby Cam TV-IP743SIC has a password of admin for the backdoor root account.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-2881

    Last Modified: 20 Apr 2025

    Gynoii has a password of guest for the backdoor guest account and a password of 12345 for the backdoor admin account.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-2882

    Last Modified: 20 Apr 2025

    Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a password of merlin for the backdoor mg3500 account, a password of M100-4674448 for the backdoor user account, and a password of M100-4674448 for the backdoor admin account.

    Published: 10 Apr 2017
    5.4
    Medium

    CVE-2015-2883

    Last Modified: 20 Apr 2025

    Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to deviceSettings.php or shareDevice.php.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2015-2884

    Last Modified: 20 Apr 2025

    Philips In.Sight B120/37 allows remote attackers to obtain sensitive information via a direct request, related to yoics.net URLs, stream.m3u8 URIs, and cam_service_enable.cgi.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-2885

    Last Modified: 20 Apr 2025

    Lens Peek-a-View has a password of 2601hx for the backdoor admin account, a password of user for the backdoor user account, and a password of guest for the backdoor guest account.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2015-2886

    Last Modified: 20 Apr 2025

    iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-2887

    Last Modified: 20 Apr 2025

    iBaby M3S has a password of admin for the backdoor admin account.

    Published: 10 Apr 2017
    8.8
    High

    CVE-2015-2889

    Last Modified: 20 Apr 2025

    Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to gain privileges via manual entry of a Settings URL.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2015-7263

    Last Modified: 20 Apr 2025

    The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value.

    Published: 10 Apr 2017
    7.8
    High

    CVE-2015-7270

    Last Modified: 20 Apr 2025

    Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-7272

    Last Modified: 20 Apr 2025

    Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long SSH username or input.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-7292

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attackers to cause a denial of service (panic) or possibly have unspecified other impact via a long string to /dev/hv.

    Published: 10 Apr 2017
    4.3
    Medium

    CVE-2016-4320

    Last Modified: 20 Apr 2025

    Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.

    Published: 10 Apr 2017
    8.8
    High

    CVE-2016-5071

    Last Modified: 20 Apr 2025

    Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root.

    Published: 10 Apr 2017
    6.1
    Medium

    CVE-2016-5078

    Last Modified: 20 Apr 2025

    Paessler PRTG before 16.2.24.4045 has XSS via SNMP.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2014-2960

    Last Modified: 20 Apr 2025

    Vision Critical before 2014-05-30 allows attackers to read arbitrary files via unspecified vectors, as demonstrated by image files and configuration files.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-2888

    Last Modified: 20 Apr 2025

    Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass authentication, related to the MySnapCam web service.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-7264

    Last Modified: 20 Apr 2025

    The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-7271

    Last Modified: 20 Apr 2025

    Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2015-8258

    Last Modified: 20 Apr 2025

    AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability."

    Published: 10 Apr 2017
    8.8
    High

    CVE-2015-6028

    Last Modified: 20 Apr 2025

    Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.

    Published: 10 Apr 2017
    6.1
    Medium

    CVE-2015-6021

    Last Modified: 20 Apr 2025

    Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.

    Published: 10 Apr 2017
    6.1
    Medium

    CVE-2015-6027

    Last Modified: 20 Apr 2025

    Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.

    Published: 10 Apr 2017
    6.1
    Medium

    CVE-2015-6035

    Last Modified: 20 Apr 2025

    Opsview before 2015-11-06 has XSS via SNMP.

    Published: 10 Apr 2017
    7.8
    High

    CVE-2015-7260

    Last Modified: 20 Apr 2025

    Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable file.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2015-7265

    Last Modified: 20 Apr 2025

    Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-7273

    Last Modified: 20 Apr 2025

    Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.

    Published: 10 Apr 2017
    8.8
    High

    CVE-2015-7274

    Last Modified: 20 Apr 2025

    Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands.

    Published: 10 Apr 2017
    6.1
    Medium

    CVE-2015-7275

    Last Modified: 20 Apr 2025

    Dell Integrated Remote Access Controller (iDRAC) 6 before 2.85 and 7/8 before 2.30.30.30 has XSS.

    Published: 10 Apr 2017
    8.8
    High

    CVE-2015-8255

    Last Modified: 20 Apr 2025

    AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.

    Published: 10 Apr 2017
    5.5
    Medium

    CVE-2015-8275

    Last Modified: 20 Apr 2025

    LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC files.

    Published: 10 Apr 2017
    5.5
    Medium

    CVE-2015-8276

    Last Modified: 20 Apr 2025

    LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to read arbitrary files via crafted EDOC files.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2016-5058

    Last Modified: 20 Apr 2025

    OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.

    Published: 10 Apr 2017