CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2016-10204

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.

    Published: 3 Mar 2017
    6.1
    Medium

    CVE-2017-5571

    Last Modified: 20 Apr 2025

    Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 3 Mar 2017
    7.8
    High

    CVE-2017-5613

    Last Modified: 20 Apr 2025

    Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.

    Published: 3 Mar 2017
    6.1
    Medium

    CVE-2017-5614

    Last Modified: 20 Apr 2025

    Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.

    Published: 3 Mar 2017
    6.1
    Medium

    CVE-2017-5616

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.

    Published: 3 Mar 2017
    9.8
    Critical

    CVE-2017-5830

    Last Modified: 20 Apr 2025

    Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized data in the cookies related to the delivery scripts.

    Published: 3 Mar 2017
    6.5
    Medium

    CVE-2017-5867

    Last Modified: 20 Apr 2025

    ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of service (server hang and logfile flooding) via a one bit BMP file.

    Published: 3 Mar 2017
    6.1
    Medium

    CVE-2017-5833

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 3 Mar 2017
    3.7
    Low

    CVE-2017-5865

    Last Modified: 20 Apr 2025

    The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts.

    Published: 3 Mar 2017
    4.3
    Medium

    CVE-2017-5866

    Last Modified: 20 Apr 2025

    The autocomplete feature in the E-Mail share dialog in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2017-6471

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-wsp.c by validating the capability length.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2017-6467

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a Netscaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by changing the restrictions on file size.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2017-6468

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser crash, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating the relationship between pages and records.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2017-6469

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an LDSS dissector crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-ldss.c by ensuring that memory is allocated for a certain data structure.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2017-6470

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an IAX2 infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-iax2.c by constraining packet lateness.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2017-6473

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a malformed capture file. This was addressed in wiretap/k12.c by validating the relationships between lengths and offsets.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2017-6474

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser infinite loop, triggered by a malformed capture file. This was addressed in wiretap/netscaler.c by validating record sizes.

    Published: 3 Mar 2017
    4.8
    Medium

    CVE-2017-7400

    Last Modified: 20 Apr 2025

    OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.

    Published: 3 Mar 2017
    9.8
    Critical

    CVE-2017-9264

    Last Modified: 20 Apr 2025

    In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extract_l4_tcp`, and `extract_l4_udp` that can be triggered remotely.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2017-6472

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an RTMPT dissector infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-rtmpt.c by properly incrementing a certain sequence value.

    Published: 3 Mar 2017
    5.5
    Medium

    CVE-2017-6951

    Last Modified: 20 Apr 2025

    The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.

    Published: 3 Mar 2017
    5.9
    Medium

    CVE-2016-9892

    Last Modified: 20 Apr 2025

    The esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not properly verify X.509 certificates from the edf.eset.com SSL server, which allows man-in-the-middle attackers to spoof this server and provide crafted responses to license activation requests via a self-signed certificate. NOTE: this issue can be combined with CVE-2016-0718 to execute arbitrary code remotely as root.

    Published: 2 Mar 2017
    6.1
    Medium

    CVE-2017-6102

    Last Modified: 20 Apr 2025

    Persistent XSS in wordpress plugin rockhoist-badges v1.2.2.

    Published: 2 Mar 2017
    6.1
    Medium

    CVE-2017-6103

    Last Modified: 20 Apr 2025

    Persistent XSS Vulnerability in Wordpress plugin AnyVar v0.1.1.

    Published: 2 Mar 2017
    7.5
    High

    CVE-2017-6104

    Last Modified: 20 Apr 2025

    Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.

    Published: 2 Mar 2017
    7.8
    High

    CVE-2017-5232

    Last Modified: 20 Apr 2025

    All editions of Rapid7 Nexpose installers prior to version 6.4.24 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

    Published: 2 Mar 2017
    7.1
    High

    CVE-2017-5228

    Last Modified: 20 Apr 2025

    All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

    Published: 2 Mar 2017
    7.1
    High

    CVE-2017-5229

    Last Modified: 20 Apr 2025

    All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

    Published: 2 Mar 2017
    7.2
    High

    CVE-2017-5230

    Last Modified: 20 Apr 2025

    The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not modifiable by the user. The keystore provides storage for saved scan credentials in an otherwise secure location on disk.

    Published: 2 Mar 2017
    7.1
    High

    CVE-2017-5231

    Last Modified: 20 Apr 2025

    All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance.

    Published: 2 Mar 2017
    7.8
    High

    CVE-2017-5233

    Last Modified: 20 Apr 2025

    Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

    Published: 2 Mar 2017
    7.8
    High

    CVE-2017-5234

    Last Modified: 20 Apr 2025

    Rapid7 Insight Collector installers prior to version 1.0.16 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

    Published: 2 Mar 2017
    7.8
    High

    CVE-2017-5235

    Last Modified: 20 Apr 2025

    Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

    Published: 2 Mar 2017
    7
    High

    CVE-2017-6408

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. A local-privilege-escalation race condition in pbx_exchange can occur when a local user connects to a socket before permissions are secured.

    Published: 2 Mar 2017
    9.8
    Critical

    CVE-2017-6409

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Unauthenticated CORBA interfaces permit inappropriate access.

    Published: 2 Mar 2017
    6.1
    Medium

    CVE-2017-6393

    Last Modified: 20 Apr 2025

    An issue was discovered in NagVis 1.9b12. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "nagvis-master/share/userfiles/gadgets/std_table.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 2 Mar 2017
    8.8
    High

    CVE-2017-6400

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged command execution on NetBackup Server and Client can occur (on the local system).

    Published: 2 Mar 2017
    6.1
    Medium

    CVE-2017-6392

    Last Modified: 20 Apr 2025

    An issue was discovered in Kaltura server Lynx-12.11.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "server-Lynx-12.11.0/admin_console/web/tools/XmlJWPlayer.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 2 Mar 2017
    6.1
    Medium

    CVE-2017-6390

    Last Modified: 20 Apr 2025

    An issue was discovered in whatanime.ga before c334dd8499a681587dd4199e90b0aa0eba814c1d. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "whatanime.ga-master/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 2 Mar 2017
    6.1
    Medium

    CVE-2017-6391

    Last Modified: 20 Apr 2025

    An issue was discovered in Kaltura server Lynx-12.11.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "admin_console/web/tools/SimpleJWPlayer.php" URL, the "admin_console/web/tools/AkamaiBroadcaster.php" URL, the "admin_console/web/tools/bigRedButton.php" URL, and the "admin_console/web/tools/bigRedButtonPtsPoc.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 2 Mar 2017
    6.1
    Medium

    CVE-2017-6395

    Last Modified: 20 Apr 2025

    An issue was discovered in HashOver 2.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the 'hashover/scripts/widget-output.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 2 Mar 2017
    6.1
    Medium

    CVE-2017-6397

    Last Modified: 20 Apr 2025

    An issue was discovered in FlightAirMap v1.0-beta.10. The vulnerability exists due to insufficient filtration of user-supplied data in multiple parameters passed to several *-sub-menu.php pages. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 2 Mar 2017
    8.8
    High

    CVE-2017-6399

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged remote command execution on NetBackup Server and Client (on the server or a connected client) can occur.

    Published: 2 Mar 2017
    6.5
    Medium

    CVE-2017-6402

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Denial of service affecting NetBackup server can occur.

    Published: 2 Mar 2017
    9.8
    Critical

    CVE-2017-6403

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup Before 8.0 and NetBackup Appliance Before 3.0. NetBackup Cloud Storage Service uses a hardcoded username and password.

    Published: 2 Mar 2017
    5.5
    Medium

    CVE-2017-6404

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup Before 7.7 and NetBackup Appliance Before 2.7. There are world-writable log files, allowing destruction or spoofing of log data.

    Published: 2 Mar 2017
    7.5
    High

    CVE-2017-6405

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier. Hostname-based security is open to DNS spoofing.

    Published: 2 Mar 2017
    8.8
    High

    CVE-2017-6406

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Arbitrary privileged command execution, using whitelist directory escape with "../" substrings, can occur.

    Published: 2 Mar 2017
    8.8
    High

    CVE-2017-6407

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup Before 7.7.2 and NetBackup Appliance Before 2.7.2. Privileged remote command execution on NetBackup Server and Client (on the server or a connected client) can occur.

    Published: 2 Mar 2017
    7.8
    High

    CVE-2017-6401

    Last Modified: 20 Apr 2025

    An issue was discovered in Veritas NetBackup before 8.0 and NetBackup Appliance before 3.0. Local arbitrary command execution can occur when using bpcd and bpnbat.

    Published: 2 Mar 2017