CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2015-8986

    Last Modified: 20 Apr 2025

    Sandbox detection evasion vulnerability in hardware appliances in McAfee (now Intel Security) Advanced Threat Defense (MATD) 3.4.2.32 and earlier allows attackers to detect the sandbox environment, then bypass proper malware detection resulting in failure to detect a malware file (false-negative) via specially crafted malware.

    Published: 14 Mar 2017
    7
    High

    CVE-2015-8992

    Last Modified: 20 Apr 2025

    Malicious file execution vulnerability in Intel Security WebAdvisor before 4.0.2, 4.0.1 and 3.7.2 allows attackers to make the product momentarily vulnerable via executing preexisting specifically crafted malware during installation or uninstallation, but not during normal operation.

    Published: 14 Mar 2017
    5.3
    Medium

    CVE-2015-8987

    Last Modified: 20 Apr 2025

    Man-in-the-middle (MitM) attack vulnerability in non-Mac OS agents in McAfee (now Intel Security) Agent (MA) 4.8.0 patch 2 and earlier allows attackers to make a McAfee Agent talk with another, possibly rogue, ePO server via McAfee Agent migration to another ePO server.

    Published: 14 Mar 2017
    8.8
    High

    CVE-2015-8988

    Last Modified: 20 Apr 2025

    Unquoted executable path vulnerability in Client Management and Gateway components in McAfee (now Intel Security) ePO Deep Command (eDC) 2.2 and 2.1 allows authenticated users to execute a command of their choice via dropping a malicious file for the path.

    Published: 14 Mar 2017
    8.8
    High

    CVE-2015-8989

    Last Modified: 20 Apr 2025

    Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more easily decrypt user passwords via brute force attacks against the database.

    Published: 14 Mar 2017
    7.5
    High

    CVE-2015-8990

    Last Modified: 20 Apr 2025

    Detection bypass vulnerability in Intel Security Advanced Threat Defense (ATD) 3.4.6 and earlier allows malware samples to bypass ATD detection via renaming the malware.

    Published: 14 Mar 2017
    7
    High

    CVE-2015-8993

    Last Modified: 20 Apr 2025

    Malicious file execution vulnerability in Intel Security CloudAV (Beta) before 0.5.0.151.3 allows attackers to make the product momentarily vulnerable via executing preexisting specifically crafted malware during installation or uninstallation, but not during normal operation.

    Published: 14 Mar 2017
    8.8
    High

    CVE-2016-8008

    Last Modified: 20 Apr 2025

    Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of the version.dll file via McAfee McUICnt.exe onto a Windows system.

    Published: 14 Mar 2017
    7.8
    High

    CVE-2016-8009

    Last Modified: 20 Apr 2025

    Privilege escalation vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and 6.x versions allows attackers to cause DoS, unexpected behavior, or potentially unauthorized code execution via an unauthorized use of IOCTL call.

    Published: 14 Mar 2017
    7.8
    High

    CVE-2016-8010

    Last Modified: 20 Apr 2025

    Application protections bypass vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and earlier and Endpoint Security (ENS) 10.2 and earlier allows local users to bypass local security protection via a command-line utility.

    Published: 14 Mar 2017
    6.1
    Medium

    CVE-2016-8011

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Intel Security McAfee Endpoint Security (ENS) Web Control before 10.2.0.408.10 allows attackers to inject arbitrary web script or HTML via a crafted web site.

    Published: 14 Mar 2017
    7.8
    High

    CVE-2016-8012

    Last Modified: 20 Apr 2025

    Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process memory get.

    Published: 14 Mar 2017
    4.3
    Medium

    CVE-2016-8018

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to execute unauthorized commands via a crafted user input.

    Published: 14 Mar 2017
    6.1
    Medium

    CVE-2016-8019

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows unauthenticated remote attackers to inject arbitrary web script or HTML via a crafted user input.

    Published: 14 Mar 2017
    8
    High

    CVE-2016-8020

    Last Modified: 20 Apr 2025

    Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to execute arbitrary code via a crafted HTTP request parameter.

    Published: 14 Mar 2017
    5
    Medium

    CVE-2016-8021

    Last Modified: 20 Apr 2025

    Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof update server and execute arbitrary code via a crafted input file.

    Published: 14 Mar 2017
    7.5
    High

    CVE-2016-8022

    Last Modified: 20 Apr 2025

    Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to execute arbitrary code or cause a denial of service via a crafted authentication cookie.

    Published: 14 Mar 2017
    8.1
    High

    CVE-2016-8023

    Last Modified: 20 Apr 2025

    Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to bypass server authentication via a crafted authentication cookie.

    Published: 14 Mar 2017
    7.8
    High

    CVE-2016-8026

    Last Modified: 20 Apr 2025

    Arbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users to gain elevated privileges via unspecified vectors.

    Published: 14 Mar 2017
    10
    Critical

    CVE-2016-8027

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without authentication via a specially crafted HTTP post.

    Published: 14 Mar 2017
    6.5
    Medium

    CVE-2017-3899

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted HTTP request parameter.

    Published: 14 Mar 2017
    7.8
    High

    CVE-2017-6903

    Last Modified: 20 Apr 2025

    In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger loading of crafted auto-downloaded files as native code DLLs. A malicious auto-downloaded file can contain configuration defaults that override the user's. Executable bytecode in a malicious auto-downloaded file can set configuration variables to values that will result in unwanted native code DLLs being loaded, resulting in sandbox escape.

    Published: 14 Mar 2017
    Unknown

    CVE-2017-6902

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 14 Mar 2017
    8.8
    High

    CVE-2017-6896

    Last Modified: 20 Apr 2025

    Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value.

    Published: 14 Mar 2017
    3.3
    Low

    CVE-2017-5985

    Last Modified: 20 Apr 2025

    lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.

    Published: 14 Mar 2017
    6.7
    Medium

    CVE-2017-6516

    Last Modified: 20 Apr 2025

    A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system files and make restricted kernel calls. This access could be exploited by a local attacker to gain a root shell prompt using the right combination of environment variables and command line arguments.

    Published: 14 Mar 2017
    7.8
    High

    CVE-2017-2983

    Last Modified: 20 Apr 2025

    Adobe Shockwave versions 12.2.7.197 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to escalation of privilege.

    Published: 14 Mar 2017
    7.5
    High

    CVE-2016-10189

    Last Modified: 20 Apr 2025

    BitlBee before 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list.

    Published: 14 Mar 2017
    9.8
    Critical

    CVE-2016-10188

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in bitlbee-libpurple before 3.5 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code by causing a file transfer connection to expire.

    Published: 14 Mar 2017
    9.8
    Critical

    CVE-2017-5668

    Last Modified: 20 Apr 2025

    bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-10189.

    Published: 14 Mar 2017
    5.5
    Medium

    CVE-2017-5957

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the vrend_decode_set_framebuffer_state function in vrend_decode.c in virglrenderer before 926b9b3460a48f6454d8bbe9e44313d86a65447f, as used in Quick Emulator (QEMU), allows a local guest users to cause a denial of service (application crash) via the "nr_cbufs" argument.

    Published: 14 Mar 2017
    9.8
    Critical

    CVE-2013-4659

    Last Modified: 20 Apr 2025

    Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.

    Published: 14 Mar 2017
    7.5
    High

    CVE-2014-8688

    Last Modified: 20 Apr 2025

    An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in cleartext in process memory and a .db file.

    Published: 14 Mar 2017
    7.5
    High

    CVE-2016-9368

    Last Modified: 20 Apr 2025

    An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating.

    Published: 14 Mar 2017
    6.1
    Medium

    CVE-2017-6877

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim 0.7.1 and earlier allows remote attackers to inject arbitrary web script.

    Published: 14 Mar 2017
    7.5
    High

    CVE-2017-6367

    Last Modified: 20 Apr 2025

    In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an invalid Content-Length header.

    Published: 14 Mar 2017
    8.8
    High

    CVE-2017-6398

    Last Modified: 20 Apr 2025

    An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is root). Besides, the default installation of IMSVA comes with default administrator credentials. The saveCert.imss endpoint takes several user inputs and performs blacklisting. After that, it uses them as arguments to a predefined operating-system command without proper sanitization. However, because of an improper blacklisting rule, it's possible to inject arbitrary commands into it.

    Published: 14 Mar 2017
    4.7
    Medium

    CVE-2017-6883

    Last Modified: 20 Apr 2025

    The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

    Published: 14 Mar 2017
    5.5
    Medium

    CVE-2016-9603

    Last Modified: 21 Nov 2024

    A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.

    Published: 14 Mar 2017
    8.8
    High

    CVE-2017-2997

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable buffer overflow / underflow vulnerability in the Primetime TVSDK that supports customizing ad information. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Mar 2017
    8.8
    High

    CVE-2017-2999

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK functionality related to hosting playback surface. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Mar 2017
    5.5
    Medium

    CVE-2017-7718

    Last Modified: 20 Apr 2025

    hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors related to copying VGA data via the cirrus_bitblt_rop_fwd_transp_ and cirrus_bitblt_rop_fwd_ functions.

    Published: 14 Mar 2017
    4.1
    Medium

    CVE-2017-2653

    Last Modified: 21 Nov 2024

    A number of unused delete routes are present in CloudForms before 5.7.2.1 which can be accessed via GET requests instead of just POST requests. This could allow an attacker to bypass the protect_from_forgery XSRF protection causing the routes to be used. This attack would require additional cross-site scripting or similar attacks in order to execute.

    Published: 14 Mar 2017
    8.8
    High

    CVE-2017-2998

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable memory corruption vulnerability in the Primetime TVSDK API functionality related to timeline interactions. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Mar 2017
    8.8
    High

    CVE-2017-3001

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to garbage collection in the ActionScript 2 VM. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Mar 2017
    8.8
    High

    CVE-2017-3002

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability in the ActionScript2 TextField object related to the variable property. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Mar 2017
    8.8
    High

    CVE-2017-3003

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable use after free vulnerability related to an interaction between the privacy user interface and the ActionScript 2 Camera object. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Mar 2017
    6.5
    Medium

    CVE-2017-3000

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.221 and earlier have a vulnerability in the random number generator used for constant blinding. Successful exploitation could lead to information disclosure.

    Published: 14 Mar 2017
    6.1
    Medium

    CVE-2014-3926

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in lg.cgi in Cougar LG 1.9 allows remote attackers to inject arbitrary web script or HTML via the "addr" parameter.

    Published: 13 Mar 2017
    5.9
    Medium

    CVE-2015-6671

    Last Modified: 20 Apr 2025

    Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup.

    Published: 13 Mar 2017