CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2017-7388

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtration of user-supplied data (token) passed to the 'wallacepos-master/myaccount/resetpassword.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 1 Apr 2017
    6.1
    Medium

    CVE-2017-7389

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/modules/tc/webconf/webconf.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 1 Apr 2017
    6.1
    Medium

    CVE-2017-7390

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting (XSS) was discovered in 'SocialNetwork v1.2.1'. The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the 'SocialNetwork-andrea/app/template/pw_forgot.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 1 Apr 2017
    6.1
    Medium

    CVE-2017-7391

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting (XSS) was discovered in 'Magmi 0.7.22'. The vulnerability exists due to insufficient filtration of user-supplied data (prefix) passed to the 'magmi-git-master/magmi/web/ajax_gettime.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 1 Apr 2017
    5.5
    Medium

    CVE-2017-7472

    Last Modified: 20 Apr 2025

    The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.

    Published: 1 Apr 2017
    6.1
    Medium

    CVE-2017-7387

    Last Modified: 20 Apr 2025

    TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a reflected XSS in HelpMeWatchWho-master/unaired.php (episodeID parameter).

    Published: 31 Mar 2017
    6.1
    Medium

    CVE-2017-7386

    Last Modified: 20 Apr 2025

    citymont/symetrie v.0.9.6 is vulnerable to a reflected XSS in symetrie-master/app/commands/page.php (model parameter).

    Published: 31 Mar 2017
    7.3
    High

    CVE-2016-8032

    Last Modified: 20 Apr 2025

    Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attackers to bypass local security protection via a crafted input file.

    Published: 31 Mar 2017
    7.5
    High

    CVE-2016-6561

    Last Modified: 20 Apr 2025

    illumos smbsrv NULL pointer dereference allows system crash.

    Published: 31 Mar 2017
    8.6
    High

    CVE-2016-6560

    Last Modified: 20 Apr 2025

    illumos osnet-incorporation bcopy() and bzero() implementations make signed instead of unsigned comparisons allowing a system crash.

    Published: 31 Mar 2017
    5.4
    Medium

    CVE-2016-6022

    Last Modified: 20 Apr 2025

    IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.

    Published: 31 Mar 2017
    5.4
    Medium

    CVE-2016-6036

    Last Modified: 20 Apr 2025

    IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.

    Published: 31 Mar 2017
    9.1
    Critical

    CVE-2016-6111

    Last Modified: 20 Apr 2025

    IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000833.

    Published: 31 Mar 2017
    6.1
    Medium

    CVE-2016-9990

    Last Modified: 20 Apr 2025

    IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998824.

    Published: 31 Mar 2017
    5.4
    Medium

    CVE-2016-8935

    Last Modified: 20 Apr 2025

    IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999483.

    Published: 31 Mar 2017
    7.5
    High

    CVE-2017-2775

    Last Modified: 20 Apr 2025

    An exploitable memory corruption vulnerability exists in the LvVariantUnflatten functionality in 64-bit versions of LabVIEW before 2015 SP1 f7 Patch and 2016 before f2 Patch. A specially crafted VI file can cause a user controlled value to be used as a loop terminator resulting in internal heap corruption. An attacker controlled VI file can be used to trigger this vulnerability, exploitation could lead to remote code execution.

    Published: 31 Mar 2017
    5.4
    Medium

    CVE-2016-6031

    Last Modified: 20 Apr 2025

    IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000784.

    Published: 31 Mar 2017
    8.8
    High

    CVE-2016-8917

    Last Modified: 20 Apr 2025

    IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000943.

    Published: 31 Mar 2017
    8.1
    High

    CVE-2016-9707

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 2000784.

    Published: 31 Mar 2017
    6.5
    Medium

    CVE-2017-1154

    Last Modified: 20 Apr 2025

    IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users. IBM Reference #: 1999892.

    Published: 31 Mar 2017
    4.3
    Medium

    CVE-2017-1171

    Last Modified: 20 Apr 2025

    The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to execute Application actions they do not have access to. IBM Reference #: 2001083.

    Published: 31 Mar 2017
    9.8
    Critical

    CVE-2014-3931

    Last Modified: 21 Apr 2026

    fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.

    Published: 31 Mar 2017
    9.8
    Critical

    CVE-2017-3010

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the rendering engine. Successful exploitation could lead to arbitrary code execution.

    Published: 31 Mar 2017
    7.5
    High

    CVE-2017-3009

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow vulnerability in the JPEG2000 parser. Successful exploitation could lead to information disclosure.

    Published: 31 Mar 2017
    7.5
    High

    CVE-2015-4624

    Last Modified: 20 Apr 2025

    Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.

    Published: 31 Mar 2017
    6.1
    Medium

    CVE-2017-7362

    Last Modified: 20 Apr 2025

    Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.

    Published: 31 Mar 2017
    6.1
    Medium

    CVE-2017-7363

    Last Modified: 20 Apr 2025

    Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.

    Published: 31 Mar 2017
    4.8
    Medium

    CVE-2017-6973

    Last Modified: 20 Apr 2025

    A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2.

    Published: 31 Mar 2017
    4.8
    Medium

    CVE-2017-7309

    Last Modified: 20 Apr 2025

    A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option' parameter. This is fixed in 1.3.9, 2.1.3, and 2.2.3.

    Published: 31 Mar 2017
    6.1
    Medium

    CVE-2017-7361

    Last Modified: 20 Apr 2025

    Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.

    Published: 31 Mar 2017
    6.1
    Medium

    CVE-2017-7359

    Last Modified: 20 Apr 2025

    Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.

    Published: 31 Mar 2017
    6.1
    Medium

    CVE-2017-7360

    Last Modified: 20 Apr 2025

    Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.

    Published: 31 Mar 2017
    4.8
    Medium

    CVE-2017-7241

    Last Modified: 20 Apr 2025

    A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) settings allows it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. Note that this vulnerability is not exploitable if the admin tools directory is removed, as recommended in the "Post-installation and upgrade tasks" of the MantisBT Admin Guide. A reminder to do so is also displayed on the login page.

    Published: 31 Mar 2017
    9.8
    Critical

    CVE-2017-12424

    Last Modified: 20 Apr 2025

    In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.

    Published: 31 Mar 2017
    5.9
    Medium

    CVE-2016-9319

    Last Modified: 20 Apr 2025

    There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.

    Published: 31 Mar 2017
    5.5
    Medium

    CVE-2017-8106

    Last Modified: 20 Apr 2025

    The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointer.

    Published: 31 Mar 2017
    7.8
    High

    CVE-2017-7374

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.

    Published: 31 Mar 2017
    6.5
    Medium

    CVE-2017-7606

    Last Modified: 20 Apr 2025

    coders/rle.c in ImageMagick 7.0.5-4 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

    Published: 31 Mar 2017
    8.8
    High

    CVE-2017-7253

    Last Modified: 20 Apr 2025

    Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the target IP camera. During exploitation, the first JSON object encountered has a "Component error: login challenge!" message. The second JSON object encountered has a result indicating a successful admin login.

    Published: 30 Mar 2017
    5.3
    Medium

    CVE-2017-5184

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration).

    Published: 30 Mar 2017
    7.2
    High

    CVE-2017-6183

    Last Modified: 20 Apr 2025

    In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NSWA-1314.

    Published: 30 Mar 2017
    7.5
    High

    CVE-2017-5185

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.

    Published: 30 Mar 2017
    9.8
    Critical

    CVE-2017-6182

    Last Modified: 20 Apr 2025

    In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.

    Published: 30 Mar 2017
    8.1
    High

    CVE-2017-6412

    Last Modified: 20 Apr 2025

    In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.

    Published: 30 Mar 2017
    4.7
    Medium

    CVE-2017-6184

    Last Modified: 20 Apr 2025

    In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.

    Published: 30 Mar 2017
    5.9
    Medium

    CVE-2016-7541

    Last Modified: 20 Apr 2025

    Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate's IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (the default mode) are not affected.

    Published: 30 Mar 2017
    4.9
    Medium

    CVE-2016-7542

    Last Modified: 20 Apr 2025

    A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.

    Published: 30 Mar 2017
    9.8
    Critical

    CVE-2016-10306

    Last Modified: 20 Apr 2025

    Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.

    Published: 30 Mar 2017
    9.8
    Critical

    CVE-2016-10305

    Last Modified: 20 Apr 2025

    Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update package on a Trango FTP server. This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.

    Published: 30 Mar 2017
    9.8
    Critical

    CVE-2016-10307

    Last Modified: 20 Apr 2025

    Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to the underlying embedded UNIX OS on the device, allowing full control over it.

    Published: 30 Mar 2017