CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-0503

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-28449045. References: M-ALPS02710075.

    Published: 8 Mar 2017
    7.8
    High

    CVE-2017-0505

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-31822282. References: M-ALPS02992041.

    Published: 8 Mar 2017
    7.8
    High

    CVE-2017-0510

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the kernel FIQ debugger could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-32402555.

    Published: 8 Mar 2017
    7.8
    High

    CVE-2017-0333

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33899363. References: N-CVE-2017-0333.

    Published: 8 Mar 2017
    5.5
    Medium

    CVE-2017-0334

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.18. Android ID: A-33245849. References: N-CVE-2017-0334.

    Published: 8 Mar 2017
    7
    High

    CVE-2017-0521

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32919951. References: QC-CR#1097709.

    Published: 8 Mar 2017
    7.8
    High

    CVE-2017-0528

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the kernel security subsystem could enable a local malicious application to to execute code in the context of a privileged process. This issue is rated as High because it is a general bypass for a kernel level defense in depth or exploit mitigation technology. Product: Android. Versions: Kernel-3.18. Android ID: A-33351919.

    Published: 8 Mar 2017
    4.7
    Medium

    CVE-2017-0536

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33555878.

    Published: 8 Mar 2017
    7.8
    High

    CVE-2017-0335

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33043375. References: N-CVE-2017-0335.

    Published: 8 Mar 2017
    7.8
    High

    CVE-2017-0337

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-31992762. References: N-CVE-2017-0337.

    Published: 8 Mar 2017
    4.7
    Medium

    CVE-2017-0461

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32073794. References: QC-CR#1100132.

    Published: 8 Mar 2017
    7.8
    High

    CVE-2017-0467

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33250932.

    Published: 8 Mar 2017
    7.8
    High

    CVE-2017-0480

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32705429.

    Published: 8 Mar 2017
    5.5
    Medium

    CVE-2017-0487

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-33751193.

    Published: 8 Mar 2017
    5.5
    Medium

    CVE-2017-0494

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32764144.

    Published: 8 Mar 2017
    7.8
    High

    CVE-2017-0307

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33177895. References: N-CVE-2017-0307.

    Published: 8 Mar 2017
    9.8
    Critical

    CVE-2017-7857

    Last Modified: 20 Apr 2025

    FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.

    Published: 8 Mar 2017
    4.3
    Medium

    CVE-2017-2662

    Last Modified: 21 Nov 2024

    A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.

    Published: 8 Mar 2017
    6.1
    Medium

    CVE-2017-6518

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in /sanadata/seo/index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the txtFrom parameter.

    Published: 8 Mar 2017
    5.9
    Medium

    CVE-2016-9245

    Last Modified: 20 Apr 2025

    In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with BIG-IP APM profiles, regardless of settings. The issue is also exposed with the non-default "Normalize URI" configuration options used in iRules and/or BIG-IP LTM policies. An attacker may be able to disrupt traffic or cause the BIG-IP system to fail over to another device in the device group.

    Published: 7 Mar 2017
    6.1
    Medium

    CVE-2017-6511

    Last Modified: 5 May 2025

    andrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in application/classes/application.php.

    Published: 7 Mar 2017
    7.5
    High

    CVE-2017-5681

    Last Modified: 20 Apr 2025

    The RSA-CRT implementation in the Intel QuickAssist Technology (QAT) Engine for OpenSSL versions prior to 0.5.19 may allow remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.

    Published: 7 Mar 2017
    4.3
    Medium

    CVE-2016-9730

    Last Modified: 20 Apr 2025

    IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.

    Published: 7 Mar 2017
    5.4
    Medium

    CVE-2017-1133

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.

    Published: 7 Mar 2017
    8.8
    High

    CVE-2016-8940

    Last Modified: 20 Apr 2025

    IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific database tables may allow access to passwords or other sensitive information for the product. IBM Reference #: 1998946.

    Published: 7 Mar 2017
    6.1
    Medium

    CVE-2016-9723

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534.

    Published: 7 Mar 2017
    8.1
    High

    CVE-2016-9724

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999537.

    Published: 7 Mar 2017
    6.5
    Medium

    CVE-2016-8971

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault which would result in the box having to be rebooted to resume normal operations. IBM Reference #: 1998663.

    Published: 7 Mar 2017
    5.3
    Medium

    CVE-2016-9720

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Reference #: 1999533.

    Published: 7 Mar 2017
    5.3
    Medium

    CVE-2016-9725

    Last Modified: 20 Apr 2025

    IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources from external sites, avoiding the need to duplicate them. IBM Reference #: 1999539.

    Published: 7 Mar 2017
    8.8
    High

    CVE-2016-9726

    Last Modified: 20 Apr 2025

    IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM Reference #: 1999542.

    Published: 7 Mar 2017
    8.5
    High

    CVE-2016-9727

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM Reference #: 1999542.

    Published: 7 Mar 2017
    7.5
    High

    CVE-2016-9728

    Last Modified: 20 Apr 2025

    IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Reference #: 1999543.

    Published: 7 Mar 2017
    6.5
    Medium

    CVE-2016-9729

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM Reference #: 1999545.

    Published: 7 Mar 2017
    7.5
    High

    CVE-2016-9740

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 could allow a remote attacker to consume all resources on the server due to not properly restricting the size or amount of resources requested by an actor. IBM Reference #: 1999556.

    Published: 7 Mar 2017
    2.9
    Low

    CVE-2017-1124

    Last Modified: 20 Apr 2025

    IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local attacker to obtain sensitive information using HTTP Header Injection. IBM Reference #: 1998053.

    Published: 7 Mar 2017
    6.1
    Medium

    CVE-2016-9693

    Last Modified: 20 Apr 2025

    IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cause an unauthenticated victim to download a malicious payload. An existing file type restriction can be bypassed so that the payload might be considered executable and cause damage on the victim's machine. IBM Reference #: 1998655.

    Published: 7 Mar 2017
    9.8
    Critical

    CVE-2016-7789

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.

    Published: 7 Mar 2017
    6.1
    Medium

    CVE-2016-4948

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Template Name field when renaming a template; (2) KDC Server host, (3) Kerberos Security Realm, (4) Kerberos Encryption Types, (5) Advanced Configuration Snippet (Safety Valve) for [libdefaults] section of krb5.conf, (6) Advanced Configuration Snippet (Safety Valve) for the Default Realm in krb5.conf, (7) Advanced Configuration Snippet (Safety Valve) for remaining krb5.conf, or (8) Active Directory Account Prefix fields in the Kerberos wizard; or (9) classicWizard parameter to cmf/cloudera-director/redirect.

    Published: 7 Mar 2017
    5.5
    Medium

    CVE-2016-6242

    Last Modified: 20 Apr 2025

    OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion failure and kernel panic) via a large ident value in a kevent system call.

    Published: 7 Mar 2017
    5.5
    Medium

    CVE-2016-6243

    Last Modified: 20 Apr 2025

    thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp parameter of the __thrsleep system call.

    Published: 7 Mar 2017
    9.8
    Critical

    CVE-2016-7780

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.

    Published: 7 Mar 2017
    9.8
    Critical

    CVE-2016-7788

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 7 Mar 2017
    9.8
    Critical

    CVE-2016-9019

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.

    Published: 7 Mar 2017
    6.1
    Medium

    CVE-2017-6509

    Last Modified: 20 Apr 2025

    Smith0r/burgundy-cms before 2017-03-06 is vulnerable to a reflected XSS in admin/components/menu/views/menuitems.php (id parameter).

    Published: 7 Mar 2017
    5.3
    Medium

    CVE-2016-4947

    Last Modified: 20 Apr 2025

    Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.

    Published: 7 Mar 2017
    7.5
    High

    CVE-2016-4949

    Last Modified: 20 Apr 2025

    Cloudera Manager 5.5 and earlier allows remote attackers to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename parameter to /cmf/process/<process_id>/logs.

    Published: 7 Mar 2017
    7.5
    High

    CVE-2016-4950

    Last Modified: 20 Apr 2025

    Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sessions.

    Published: 7 Mar 2017
    7.8
    High

    CVE-2016-6241

    Last Modified: 20 Apr 2025

    Integer overflow in the amap_alloc1 function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a large size value.

    Published: 7 Mar 2017
    5.5
    Medium

    CVE-2016-6239

    Last Modified: 20 Apr 2025

    The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value.

    Published: 7 Mar 2017